CVE-2020-29368

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.

References

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c444eb564fb16645c172d550359cb3d75fe8a040

https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.5

https://bugs.chromium.org/p/project-zero/issues/detail?id=2045

https://security.netapp.com/advisory/ntap-20210108-0002/

Details

Source: MITRE

Published: 2020-11-28

Updated: 2021-07-21

Type: CWE-787

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
151307EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2021-2075)NessusHuawei Local Security Checks
high
148700SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1210-1)NessusSuSE Local Security Checks
high
148509SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1175-1)NessusSuSE Local Security Checks
medium
147982Ubuntu 20.04 LTS : Linux kernel (OEM) vulnerabilities (USN-4752-1)NessusUbuntu Local Security Checks
high
147690EulerOS Virtualization 2.9.0 : kernel (EulerOS-SA-2021-1642)NessusHuawei Local Security Checks
high
147591SUSE SLES15 Security Update : kernel (SUSE-SU-2021:0735-1)NessusSuSE Local Security Checks
high
147586SUSE SLES15 Security Update : kernel (SUSE-SU-2021:0740-1)NessusSuSE Local Security Checks
high
147579SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:0741-1)NessusSuSE Local Security Checks
high
147568SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0736-1)NessusSuSE Local Security Checks
high
147563openSUSE Security Update : the Linux Kernel (openSUSE-2021-393)NessusSuSE Local Security Checks
high
147512EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-1604)NessusHuawei Local Security Checks
high
147464SUSE SLES15 Security Update : kernel (SUSE-SU-2021:0737-1)NessusSuSE Local Security Checks
high
144693EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-1028)NessusHuawei Local Security Checks
high
144687EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-1009)NessusHuawei Local Security Checks
high
144168EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-2514)NessusHuawei Local Security Checks
medium