CVE-2020-10757: Buffer Overflow
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
Other sources
A flaw was found in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
A flaw was found in the way mremap handled DAX hugepages. A local attacker could use this flaw to escalate their privileges on the system by being able to control PTEs and effectively creating physical to virtual mappings at will.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1127.18.2.rt56.1116.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.58.2.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.33.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.13.2.rt13.65.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.13.2.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.27.1.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.24.2.el8_1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Compensating control
Do not use DAX enabled storage (mitigation to prevent exploitation of the mremap DAX huge pages flaw).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-10757?
CVE-2020-10757 has been classified with a medium severity level due to its potential for privilege escalation.
How do I fix CVE-2020-10757?
To fix CVE-2020-10757, update your Linux Kernel to versions 3.10.0-1127.18.2.el7 or later, or follow your distribution's recommendations for patches.
Who is affected by CVE-2020-10757?
CVE-2020-10757 affects versions of the Linux Kernel after 4.5-rc1, particularly systems using DAX enabled storage.
What type of vulnerability is CVE-2020-10757?
CVE-2020-10757 is a privilege escalation vulnerability related to how the Linux Kernel handles DAX Huge Pages.
What is the impact of CVE-2020-10757?
The impact of CVE-2020-10757 allows a local attacker to escalate their privileges on the system if they have access to vulnerable DAX enabled storage.