First published: Mon Jun 01 2020(Updated: )
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1127.18.2.rt56.1116.el7 | 0:3.10.0-1127.18.2.rt56.1116.el7 |
redhat/kernel | <0:3.10.0-1127.18.2.el7 | 0:3.10.0-1127.18.2.el7 |
redhat/kernel | <0:3.10.0-957.58.2.el7 | 0:3.10.0-957.58.2.el7 |
redhat/kernel | <0:3.10.0-1062.33.1.el7 | 0:3.10.0-1062.33.1.el7 |
redhat/kernel-rt | <0:4.18.0-193.13.2.rt13.65.el8_2 | 0:4.18.0-193.13.2.rt13.65.el8_2 |
redhat/kernel | <0:4.18.0-193.13.2.el8_2 | 0:4.18.0-193.13.2.el8_2 |
redhat/kernel | <0:4.18.0-80.27.1.el8_0 | 0:4.18.0-80.27.1.el8_0 |
redhat/kernel | <0:4.18.0-147.24.2.el8_1 | 0:4.18.0-147.24.2.el8_1 |
Linux Linux kernel | >=4.5<4.9.227 | |
Linux Linux kernel | >=4.10<4.14.184 | |
Linux Linux kernel | >=4.15<4.19.127 | |
Linux Linux kernel | >=4.20<5.4.45 | |
Linux Linux kernel | >=5.5<5.6.17 | |
Linux Linux kernel | >=5.7<5.7.1 | |
openSUSE Leap | =15.1 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Mrg | =2.0 | |
Fedoraproject Fedora | =31 | |
Debian Debian Linux | =8.0 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Cloud Backup | ||
Netapp Steelstore Cloud Integrated Storage | ||
Linux Linux kernel | >=4.5.1<=5.6.16 | |
Linux Linux kernel | =4.5-rc2 | |
Linux Linux kernel | =4.5-rc3 | |
Linux Linux kernel | =4.5-rc4 | |
Linux Linux kernel | =4.5-rc5 | |
Linux Linux kernel | =4.5-rc6 | |
Linux Linux kernel | =4.5-rc7 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.106-3 6.1.112-1 6.11.4-1 6.11.5-1 |
Do not use DAX enabled storage.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)