Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-25212

Опубликовано: 09 сент. 2020
Источник: debian

Описание

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.7.17-1package
linuxfixed4.19.146-1busterpackage

Примечания

  • https://git.kernel.org/linus/b4487b93545214a9db8cbf32e86411677b0cca21

Связанные уязвимости

CVSS3: 7
ubuntu
почти 5 лет назад

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

CVSS3: 7
redhat
почти 5 лет назад

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

CVSS3: 7
nvd
почти 5 лет назад

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

CVSS3: 7
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
больше 4 лет назад

Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2)