CVE-2020-10757
Vulnerability Summary
Timeline
Description
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.99%• Percentile: 61%
Techniques & Countermeasures
- CWE-119•Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
- CWE-843•Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Affected Systems
- canonical•ubuntu_linux
16.04 | 18.04 | 20.04
- debian•linux
< 5.6.14-2 | < 5.6.14-2 | < 5.6.14-2 | < 5.6.14-2
- ubuntu•linux
< 4.15.0-112.113 | < 5.4.0-45.49
- ubuntu•linux-aws
< 4.15.0-1079.83 | < 5.4.0-1022.22
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.3
< 5.3.0-1032.34~18.04.2
- ubuntu•linux-aws-5.4
< 5.4.0-1022.22~18.04.1
- ubuntu•linux-aws-fips
< 4.15.0-2024.24 | all | < 5.4.0-1069.73+fips2
- ubuntu•linux-aws-hwe
< 4.15.0-1079.83~16.04.1
- ubuntu•linux-azure
< 4.15.0-1092.102~14.04.1 | < 4.15.0-1092.102~16.04.1 | all | < 5.4.0-1023.23
- ubuntu•linux-azure-4.15
< 4.15.0-1092.102
- ubuntu•linux-azure-5.3
< 5.3.0-1034.35~18.04.1
- ubuntu•linux-azure-5.4
< 5.4.0-1023.23~18.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all | < 5.4.0-1073.76+fips1
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.15.0-1037.42
- ubuntu•linux-gcp
< 4.15.0-1080.90~16.04.1 | all | < 5.4.0-1022.22
- ubuntu•linux-gcp-4.15
< 4.15.0-1080.90
- ubuntu•linux-gcp-5.3
< 5.3.0-1032.34~18.04.1
- ubuntu•linux-gcp-5.4
< 5.4.0-1022.22~18.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
all | < 5.4.0-1067.71~20.04.1
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1066.69
- ubuntu•linux-gke-5.0
< 5.0.0-1045.46
- ubuntu•linux-gke-5.3
< 5.3.0-1032.34~18.04.1
- ubuntu•linux-hwe
< 4.15.0-112.113~16.04.1 | < 5.3.0-64.58~18.04.1
- ubuntu•linux-hwe-5.4
< 5.4.0-45.49~18.04.2
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.15.0-1071.72 | < 5.4.0-1021.21
- ubuntu•linux-oem
< 4.15.0-1093.103
- ubuntu•linux-oem-5.6
< 5.6.0-1018.18
- ubuntu•linux-oem-osp1
< 5.0.0-1065.70
- ubuntu•linux-oracle
< 4.15.0-1050.54~16.04.1 | < 4.15.0-1050.54 | < 5.4.0-1022.22
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.3
< 5.3.0-1030.32~18.04.1
- ubuntu•linux-oracle-5.4
< 5.4.0-1022.22~18.04.1
- ubuntu•linux-raspi
< 5.4.0-1016.17
- ubuntu•linux-raspi-5.4
< 5.4.0-1016.17~18.04.1
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.15.0-1067.71 | all
- ubuntu•linux-raspi2-5.3
< 5.3.0-1030.32~18.04.2
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
< 5.4.0-31.35 | all
- ubuntu•linux-snapdragon
< 4.15.0-1083.91
- debian•debian_linux
8.0
- fedoraproject•fedora
31
Showing first 50 affected entries in server-rendered view.
References (20)
- https://www.openwall.com/lists/oss-security/2020/06/04/4
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5bfea2d9b17f1034a68147a8b03b9789af5700f9
- https://bugzilla.redhat.com/show_bug.cgi?id=1842525
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
- https://www.debian.org/security/2020/dsa-4698
- https://www.debian.org/security/2020/dsa-4699
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IEM47BXZJLODRH5YNNZSAQ2NVM63MYMC/
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html
- https://security.netapp.com/advisory/ntap-20200702-0004/
- https://usn.ubuntu.com/4439-1/
- https://usn.ubuntu.com/4426-1/
- https://usn.ubuntu.com/4440-1/
- https://usn.ubuntu.com/4483-1/
- https://ubuntu.com/security/CVE-2020-10757
- https://ubuntu.com/security/notices/USN-4426-1
- https://ubuntu.com/security/notices/USN-4439-1
- https://ubuntu.com/security/notices/USN-4440-1
- https://ubuntu.com/security/notices/USN-4483-1
- https://www.cve.org/CVERecord?id=CVE-2020-10757
- https://security-tracker.debian.org/tracker/CVE-2020-10757