[PATCH 0/1] [SRU] [focal/linux-oem-5.6] CVE-2020-25285

Tim Gardner tim.gardner at canonical.com
Fri Mar 12 17:59:22 UTC 2021


[Impact]
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux
kernel before 5.8.8 could be used by local attackers to corrupt memory, cause
a NULL pointer dereference, or possibly have unspecified other impact, aka
CID-17743798d812.

>From the Ubuntu security team:
It was discovered that a race condition existed in the hugetlb sysctl
implementation in the Linux kernel. A privileged attacker could use this to
cause a denial of service (system crash).

[Test Plan]
none

[Where problems could occur]
Released in 
linux-4.14.y
linux-4.19.y
linux-4.4.y
linux-4.9.y
linux-5.4.y
linux-5.8.y




More information about the kernel-team mailing list