7

CVE-2020-29368

Exploit
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.5.5 < 4.9.228
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.185
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.129
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.48
Linux ≫ Linux Kernel Version >= 5.5 < 5.7.5
Netapp ≫ Cloud Backup Version -
Netapp ≫ Element Software Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Hci Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.277
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://bugs.chromium.org/p/project-zero/issues/detail?id=2045
Patch
Third Party Advisory
Exploit
Issue Tracking
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.5
Vendor Advisory
Release Notes
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c444eb564fb16645c172d550359cb3d75fe8a040
Patch
Vendor Advisory
https://security.netapp.com/advisory/ntap-20210108-0002/
Third Party Advisory