CVE-2020-9391: Medium severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-9391?
CVE-2020-9391 is a vulnerability in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture.
How does CVE-2020-9391 affect the Linux kernel?
CVE-2020-9391 allows an attacker to move the memory break downwards when the application expects it to move upwards, potentially causing issues.
Which systems are affected by CVE-2020-9391?
The Linux kernel versions 5.4 and 5.5 through 5.5.6 on the AArch64 architecture are affected.
What is the severity of CVE-2020-9391?
CVE-2020-9391 has a severity rating of medium.
How can I fix CVE-2020-9391?
Updating to a version of the Linux kernel that is not affected by CVE-2020-9391 is recommended.