First published: Sat Nov 28 2020(Updated: )
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <5.7.3 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
netapp 500f firmware | ||
netapp 500f | ||
netapp a250 firmware | ||
netapp a250 | ||
netapp h410c firmware | ||
netapp h410c | ||
netapp solidfire \& hci management node | ||
netapp solidfire \& hci storage node | ||
NetApp HCI Compute Node BIOS | ||
All of | ||
netapp 500f firmware | ||
netapp 500f | ||
All of | ||
netapp a250 firmware | ||
netapp a250 | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
NetApp Baseboard Management Controller 500F | ||
NetApp FAS/AFF Baseboard Management Controller | ||
NetApp Baseboard Management Controller A250 | ||
NetApp Baseboard Management Controller A250 Firmware | ||
netapp baseboard management controller h410c firmware | ||
netapp baseboard management controller h410c | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.13-1 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-29374 has been classified with a high severity due to potential unauthorized write access in the Linux kernel.
To remediate CVE-2020-29374, update your Linux kernel to version 5.7.3 or later.
CVE-2020-29374 affects Linux kernel versions before 5.7.3.
CVE-2020-29374 impacts various operating systems including older versions of Debian and Android that utilize the vulnerable Linux kernel.
Exploitation of CVE-2020-29374 could allow an attacker to gain unintended write access to memory pages, leading to data corruption or system compromise.