CVE Vulnerabilities

CVE-2020-9844

Double Free

Published: Jun 09, 2020 | Modified: Jan 09, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

A double free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 13.5 (excluding)
Iphone_os Apple * 13.5 (excluding)
Mac_os_x Apple 10.13 (including) 10.13.6 (excluding)
Mac_os_x Apple 10.14 (including) 10.14.6 (excluding)
Mac_os_x Apple 10.15 (including) 10.15.5 (excluding)
Mac_os_x Apple 10.13.6 (including) 10.13.6 (including)
Mac_os_x Apple 10.13.6-security_update_2018-002 (including) 10.13.6-security_update_2018-002 (including)
Mac_os_x Apple 10.13.6-security_update_2018-003 (including) 10.13.6-security_update_2018-003 (including)
Mac_os_x Apple 10.13.6-security_update_2019-001 (including) 10.13.6-security_update_2019-001 (including)
Mac_os_x Apple 10.13.6-security_update_2019-002 (including) 10.13.6-security_update_2019-002 (including)
Mac_os_x Apple 10.13.6-security_update_2019-003 (including) 10.13.6-security_update_2019-003 (including)
Mac_os_x Apple 10.13.6-security_update_2019-004 (including) 10.13.6-security_update_2019-004 (including)
Mac_os_x Apple 10.13.6-security_update_2019-005 (including) 10.13.6-security_update_2019-005 (including)
Mac_os_x Apple 10.13.6-security_update_2019-006 (including) 10.13.6-security_update_2019-006 (including)
Mac_os_x Apple 10.13.6-security_update_2019-007 (including) 10.13.6-security_update_2019-007 (including)
Mac_os_x Apple 10.13.6-security_update_2020-001 (including) 10.13.6-security_update_2020-001 (including)
Mac_os_x Apple 10.13.6-security_update_2020-002 (including) 10.13.6-security_update_2020-002 (including)
Mac_os_x Apple 10.14.6 (including) 10.14.6 (including)
Mac_os_x Apple 10.14.6-security_update_2019-001 (including) 10.14.6-security_update_2019-001 (including)
Mac_os_x Apple 10.14.6-security_update_2019-002 (including) 10.14.6-security_update_2019-002 (including)
Mac_os_x Apple 10.14.6-security_update_2019-004 (including) 10.14.6-security_update_2019-004 (including)
Mac_os_x Apple 10.14.6-security_update_2019-005 (including) 10.14.6-security_update_2019-005 (including)
Mac_os_x Apple 10.14.6-security_update_2019-006 (including) 10.14.6-security_update_2019-006 (including)
Mac_os_x Apple 10.14.6-security_update_2019-007 (including) 10.14.6-security_update_2019-007 (including)
Mac_os_x Apple 10.14.6-security_update_2020-001 (including) 10.14.6-security_update_2020-001 (including)
Mac_os_x Apple 10.14.6-security_update_2020-002 (including) 10.14.6-security_update_2020-002 (including)

Potential Mitigations

References