CVE-2020-25285: Race Condition
A flaw was found in the Linux kernels sysctl handling code for hugepages management. When multiple root level processes would write to modify the /proc/sys/vm/nrhugepages file it could create a race on internal variables leading to a system crash or memory corruption.
Other sources
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact
References: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=17743798d81238ab13050e8e2833699b54e15467 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.8
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.rt7.72.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.8.8Patch CID-17743798d812
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-25285?
CVE-2020-25285 is rated as high severity due to the potential for a system crash or memory corruption.
How do I fix CVE-2020-25285?
To mitigate CVE-2020-25285, upgrade to the latest patched kernel versions as recommended by your distribution.
Which versions of the Linux kernel are affected by CVE-2020-25285?
CVE-2020-25285 affects Linux kernel versions prior to 5.8.8.
Can CVE-2020-25285 be exploited remotely?
CVE-2020-25285 requires local access to the system to exploit, making it a local vulnerability.
What specific packages are impacted by CVE-2020-25285?
Packages affected by CVE-2020-25285 include various versions of the kernel, kernel-rt, and Linux distributions like Debian and Ubuntu.