CVE-2020-12768: Medium severity Linux Linux kernel vulnerability
DISPUTED An issue was discovered in the Linux kernel before 5.6. svmcpuuninit in arch/x86/kvm/svm.c has a memory leak, aka CID-d80b64ff297e. NOTE: third parties dispute this issue because it's a one-time leak at the boot, the size is negligible, and it can't be triggered at will.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CID-d80b64ff297e
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12768?
The severity of CVE-2020-12768 is generally considered low, as it involves a minor one-time memory leak during boot.
How do I fix CVE-2020-12768?
To fix CVE-2020-12768, update the Linux kernel to version 5.10.223-1 or higher.
Which Linux distributions are affected by CVE-2020-12768?
CVE-2020-12768 affects versions of the Linux kernel prior to 5.6, as well as specific releases of Ubuntu and Debian.
Can CVE-2020-12768 be exploited remotely?
No, CVE-2020-12768 cannot be exploited remotely as the memory leak occurs only at boot time.
Is CVE-2020-12768 a serious threat to my system?
CVE-2020-12768 is not considered a serious threat since it represents a minor leak that does not impact runtime performance.