First published: Tue Feb 25 2020(Updated: )
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=5.5<=5.5.6 | |
Linux Linux kernel | =5.4 | |
Fedoraproject Fedora | =31 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Cloud Backup | ||
Netapp Data Availability Services | ||
Netapp Hci Management Node | ||
Netapp Solidfire | ||
Netapp Steelstore Cloud Integrated Storage | ||
Netapp H410c Firmware | ||
Netapp H410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9391 is a vulnerability in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture.
CVE-2020-9391 allows an attacker to move the memory break downwards when the application expects it to move upwards, potentially causing issues.
The Linux kernel versions 5.4 and 5.5 through 5.5.6 on the AArch64 architecture are affected.
CVE-2020-9391 has a severity rating of medium.
Updating to a version of the Linux kernel that is not affected by CVE-2020-9391 is recommended.