[PATCH 0/1] [SRU] [focal/linux-oem-5.6] CVE-2020-25285
Tim Gardner
tim.gardner at canonical.com
Fri Mar 12 17:59:22 UTC 2021
[Impact]
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux
kernel before 5.8.8 could be used by local attackers to corrupt memory, cause
a NULL pointer dereference, or possibly have unspecified other impact, aka
CID-17743798d812.
>From the Ubuntu security team:
It was discovered that a race condition existed in the hugetlb sysctl
implementation in the Linux kernel. A privileged attacker could use this to
cause a denial of service (system crash).
[Test Plan]
none
[Where problems could occur]
Released in
linux-4.14.y
linux-4.19.y
linux-4.4.y
linux-4.9.y
linux-5.4.y
linux-5.8.y
More information about the kernel-team
mailing list