CVE-2020-10757: Buffer Overflow
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
Other sources
A flaw was found in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
A flaw was found in the way mremap handled DAX hugepages. A local attacker could use this flaw to escalate their privileges on the system by being able to control PTEs and effectively creating physical to virtual mappings at will.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1127.18.2.rt56.1116.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.58.2.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.33.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.13.2.rt13.65.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.13.2.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.27.1.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.24.2.el8_1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Configuration
Do not use DAX enabled storage to prevent exploitation of the mremap DAX huge pages handling flaw.
Linux Kernel (mremap / DAX huge pages) DAX enabled storage = disabled
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-10757?
CVE-2020-10757 has been classified with a medium severity level due to its potential for privilege escalation.
How do I fix CVE-2020-10757?
To fix CVE-2020-10757, update your Linux Kernel to versions 3.10.0-1127.18.2.el7 or later, or follow your distribution's recommendations for patches.
Who is affected by CVE-2020-10757?
CVE-2020-10757 affects versions of the Linux Kernel after 4.5-rc1, particularly systems using DAX enabled storage.
What type of vulnerability is CVE-2020-10757?
CVE-2020-10757 is a privilege escalation vulnerability related to how the Linux Kernel handles DAX Huge Pages.
What is the impact of CVE-2020-10757?
The impact of CVE-2020-10757 allows a local attacker to escalate their privileges on the system if they have access to vulnerable DAX enabled storage.