CVE-2020-10757

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1842525

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5bfea2d9b17f1034a68147a8b03b9789af5700f9

https://www.openwall.com/lists/oss-security/2020/06/04/4

https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html

https://www.debian.org/security/2020/dsa-4699

https://www.debian.org/security/2020/dsa-4698

https://lists.fedoraproject.org/archives/list/[email protected]/message/IEM47BXZJLODRH5YNNZSAQ2NVM63MYMC/

http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html

https://security.netapp.com/advisory/ntap-20200702-0004/

https://usn.ubuntu.com/4439-1/

https://usn.ubuntu.com/4426-1/

https://usn.ubuntu.com/4440-1/

https://usn.ubuntu.com/4483-1/

Details

Source: MITRE

Published: 2020-06-09

Updated: 2021-07-21

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (48 total)

IDNameProductFamilySeverity
151229EulerOS Virtualization 3.0.6.6 : kernel (EulerOS-SA-2021-2040)NessusHuawei Local Security Checks
high
147273NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2021-0008)NessusNewStart CGSL Local Security Checks
medium
146282openSUSE Security Update : RT kernel (openSUSE-2021-242)NessusSuSE Local Security Checks
high
144831EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056)NessusHuawei Local Security Checks
critical
140378SUSE SLES15 Security Update : kernel (SUSE-SU-2020:2487-1)NessusSuSE Local Security Checks
medium
140328EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1958)NessusHuawei Local Security Checks
high
140181Ubuntu 18.04 LTS / 20.04 : Linux kernel vulnerabilities (USN-4483-1)NessusUbuntu Local Security Checks
high
140159EulerOS 2.0 SP5 : kernel (EulerOS-SA-2020-1938)NessusHuawei Local Security Checks
high
140124RHEL 7 : kernel (RHSA-2020:3598)NessusRed Hat Local Security Checks
high
139995EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-1892)NessusHuawei Local Security Checks
high
139235CentOS 7 : kernel (CESA-2020:3220)NessusCentOS Local Security Checks
medium
139219Oracle Linux 7 : kernel (ELSA-2020-3220) (deprecated)NessusOracle Linux Local Security Checks
medium
139200RHEL 7 : kernel-rt (RHSA-2020:3221)NessusRed Hat Local Security Checks
medium
139199RHEL 7 : kernel (RHSA-2020:3220)NessusRed Hat Local Security Checks
medium
139197RHEL 7 : kernel (RHSA-2020:3226)NessusRed Hat Local Security Checks
high
139187RHEL 8 : kernel (RHSA-2020:3222)NessusRed Hat Local Security Checks
medium
139137EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1807)NessusHuawei Local Security Checks
high
139028Ubuntu 18.04 LTS : linux kernel vulnerabilities (USN-4440-1)NessusUbuntu Local Security Checks
medium
139027Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-4439-1)NessusUbuntu Local Security Checks
medium
138854Amazon Linux 2 : kernel (ALAS-2020-1465)NessusAmazon Linux Local Security Checks
high
138835Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4426-1)NessusUbuntu Local Security Checks
medium
138807RHEL 8 : kernel-rt (RHSA-2020:3016)NessusRed Hat Local Security Checks
high
138805RHEL 8 : kernel (RHSA-2020:3010)NessusRed Hat Local Security Checks
high
138798RHEL 8 : kernel (RHSA-2020:3041)NessusRed Hat Local Security Checks
high
138679openSUSE Security Update : the Linux Kernel (openSUSE-2020-801)NessusSuSE Local Security Checks
medium
138643Amazon Linux AMI : kernel (ALAS-2020-1401)NessusAmazon Linux Local Security Checks
high
138488Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2020-5756)NessusOracle Linux Local Security Checks
high
138418Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5755)NessusOracle Linux Local Security Checks
high
138306SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1784-1)NessusSuSE Local Security Checks
high
138305SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1781-1)NessusSuSE Local Security Checks
high
138304SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1779-1)NessusSuSE Local Security Checks
high
138298SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1767-1)NessusSuSE Local Security Checks
high
138297SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1764-1)NessusSuSE Local Security Checks
high
138272SUSE SLES15 Security Update : kernel (SUSE-SU-2020:1663-1)NessusSuSE Local Security Checks
critical
137617SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1605-1)NessusSuSE Local Security Checks
medium
137616SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1603-1)NessusSuSE Local Security Checks
medium
137615SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1602-1)NessusSuSE Local Security Checks
medium
137613SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:1599-1)NessusSuSE Local Security Checks
medium
137612SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1597-1)NessusSuSE Local Security Checks
high
137611SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1596-1)NessusSuSE Local Security Checks
high
137608SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1587-1)NessusSuSE Local Security Checks
medium
137380Fedora 31 : kernel (2020-203ffedeb5)NessusFedora Local Security Checks
high
137341Debian DSA-4699-1 : linux - security updateNessusDebian Local Security Checks
medium
137340Debian DSA-4698-1 : linux - security updateNessusDebian Local Security Checks
medium
137339Debian DLA-2242-1 : linux-4.9 security updateNessusDebian Local Security Checks
medium
137210Fedora 32 : kernel (2020-07f0be216f)NessusFedora Local Security Checks
high
137200Photon OS 3.0: Linux PHSA-2020-3.0-0102NessusPhotonOS Local Security Checks
high
137195Photon OS 2.0: Linux PHSA-2020-2.0-0251NessusPhotonOS Local Security Checks
high