Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10757

Опубликовано: 04 июн. 2020
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

A flaw was found in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

Отчет

This issue requires access to a DAX enabled storage. This issue affects Red Hat Enterprise Linux 7 kernels starting with kernel-3.10.0-862, that is Red Hat Enterprise Linux 7.5 GA kernel. Red Hat Enterprise Linux 7 kernels prior to that version are not affected as they did not include the functionality that enabled this issue to be exploited. Red Hat Product Security is aware of this issue. Updates will be released as they become available.

Меры по смягчению последствий

Do not use DAX enabled storage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-altAffected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2020:322129.07.2020
Red Hat Enterprise Linux 7kernelFixedRHSA-2020:322029.07.2020
Red Hat Enterprise Linux 7.6 Extended Update SupportkernelFixedRHSA-2020:322629.07.2020
Red Hat Enterprise Linux 7.7 Extended Update SupportkernelFixedRHSA-2020:359801.09.2020
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2020:301621.07.2020
Red Hat Enterprise Linux 8kernelFixedRHSA-2020:301021.07.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1842525kernel: kernel: DAX hugepages not considered during mremap

EPSS

Процентиль: 68%
0.00601
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

CVSS3: 7.8
nvd
около 5 лет назад

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

CVSS3: 7.8
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 5 лет назад

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the ...

suse-cvrf
почти 5 лет назад

Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP3)

EPSS

Процентиль: 68%
0.00601
Низкий

7 High

CVSS3