APPLIED: [PATCH 0/1] [SRU] [focal/linux-oem-5.6] CVE-2020-25285

Tim Gardner tim.gardner at canonical.com
Fri Mar 19 17:51:50 UTC 2021


Applied to focal/linux-oem-5.6-next. Thanks.

-rtg

On 3/12/21 10:59 AM, Tim Gardner wrote:
> [Impact]
> A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux
> kernel before 5.8.8 could be used by local attackers to corrupt memory, cause
> a NULL pointer dereference, or possibly have unspecified other impact, aka
> CID-17743798d812.
> 
>  From the Ubuntu security team:
> It was discovered that a race condition existed in the hugetlb sysctl
> implementation in the Linux kernel. A privileged attacker could use this to
> cause a denial of service (system crash).
> 
> [Test Plan]
> none
> 
> [Where problems could occur]
> Released in
> linux-4.14.y
> linux-4.19.y
> linux-4.4.y
> linux-4.9.y
> linux-5.4.y
> linux-5.8.y
> 

-- 
-----------
Tim Gardner
Canonical, Inc



More information about the kernel-team mailing list