CVE-2020-25639: Null Pointer Dereference
A flaw was found in the Linux kernel where an unprivileged console user can crash kernel via a nouveau ioctl.
Reference: https://lists.freedesktop.org/archives/nouveau/2020-August/036682.html
Other sources
A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRMIOCTLNOUVEAUCHANNELALLOC. This flaw allows a local user to crash the system.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25639?
CVE-2020-25639 has a medium severity rating due to the potential for an unprivileged console user to crash the kernel.
How do I fix CVE-2020-25639?
To resolve CVE-2020-25639, you should upgrade your Linux kernel to version 5.12 or apply the relevant patches provided by your distribution.
Who is affected by CVE-2020-25639?
CVE-2020-25639 affects multiple Linux distributions, including specific versions of Red Hat Enterprise Linux and Fedora.
What causes the CVE-2020-25639 vulnerability?
CVE-2020-25639 is caused by a flaw in the Linux kernel's handling of a nouveau ioctl, leading to a NULL pointer dereference.
Is CVE-2020-25639 exploitability limited to specific users?
Yes, CVE-2020-25639 can be exploited by unprivileged console users on affected systems.