{"id":"UBUNTU-CVE-2020-12658","details":"** DISPUTED ** gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states \"We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.\"","modified":"2020-12-31T01:15:00Z","published":"2020-12-31T01:15:00Z","withdrawn":"2025-06-23T15:53:40Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-12658"},{"type":"REPORT","url":"https://github.com/gssapi/gssproxy/commit/cb761412e299ef907f22cd7c4146d50c8a792003"},{"type":"REPORT","url":"https://github.com/gssapi/gssproxy/compare/v0.8.2...v0.8.3"},{"type":"REPORT","url":"https://pagure.io/gssproxy/c/cb761412e299ef907f22cd7c4146d50c8a792003?branch=master"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-12658"}],"affected":[{"package":{"name":"gssproxy","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/gssproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.5.1-2","0.7.0+git20171223-2","0.8.0-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-12658.json"}},{"package":{"name":"gssproxy","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gssproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.0-1.1","0.8.2-1","0.8.2-2","0.8.2-2ubuntu0.20.04.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-12658.json"}},{"package":{"name":"gssproxy","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gssproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.4-1","0.8.4-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-12658.json"}},{"package":{"name":"gssproxy","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gssproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.1-1","0.9.2-1","0.9.2-2","0.9.2-2build1","0.9.2-2build2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-12658.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}