CVE-2020-25221: High severity linux kernel vulnerability
getgatepage in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or processvmreadv(), aka CID-9fa2dd946743.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-25221?
CVE-2020-25221 is a vulnerability in the Linux kernel that allows privilege escalation due to incorrect reference counting of the struct page that backs the vsyscall page.
How does CVE-2020-25221 affect Linux kernel?
CVE-2020-25221 affects Linux kernel versions 5.7.x and 5.8.x before 5.8.7.
What is the severity of CVE-2020-25221?
CVE-2020-25221 has a severity rating of 7.8 (high).
Which software is affected by CVE-2020-25221?
CVE-2020-25221 affects Linux kernel and Netapp Cloud Backup, Netapp Solidfire, Netapp HCI Storage Node, Netapp HCI Management Node, Netapp HCI Compute Node, and Netapp Solidfire Baseboard Management Controller.
How can I fix CVE-2020-25221?
To fix CVE-2020-25221, upgrade to Linux kernel version 5.8.7 or later.