Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12657

Опубликовано: 05 мая 2020
Источник: redhat
CVSS3: 7

Описание

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

A flaw was found in the Linux kernel's implementation of the BFQ IO scheduler. This flaw allows a local user able to groom system memory to cause kernel memory corruption and possible privilege escalation by abusing a race condition in the IO scheduler.

Меры по смягчению последствий

The default io scheduler for Red Hat Enterprise Linux 8 is the mq-deadline scheduler, however it can be configured to any of the available schedulers available on the system on a per-device basis. The schedulers in use can be verified by the block devices entry in sysfs, for example for "sda":

cat /sys/block/sda/queue/scheduler

[mq-deadline] kyber bfq none All block devices in the system will need to be changed to be mitigated. If the system workload requires bfq, this may not be an acceptable workaround however some systems may find changing io schedulers to be an acceptable workaround until system updates can be applied. See https://access.redhat.com/solutions/3756041 for how to configure the io scheduler persistently across system reboots or contact Red Hat Global Support Services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2020:242809.06.2020
Red Hat Enterprise Linux 8kernelFixedRHSA-2020:242709.06.2020
Red Hat Enterprise Linux 8kpatch-patchFixedRHSA-2020:256715.06.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionskernelFixedRHSA-2020:242909.06.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1832866kernel: use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

CVSS3: 7.8
nvd
около 5 лет назад

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

CVSS3: 7.8
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 5 лет назад

An issue was discovered in the Linux kernel before 5.6.5. There is a u ...

github
около 3 лет назад

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

7 High

CVSS3