CVE-2020-29374
Summary
| CVE | CVE-2020-29374 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-28 07:15:00 UTC |
| Updated | 2023-11-09 14:44:00 UTC |
| Description | An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58. |
Risk And Classification
Problem Types: CWE-362 | CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Hardware | Netapp | 500f | - | All | All | All |
| Operating System | Netapp | 500f Firmware | - | All | All | All |
| Hardware | Netapp | A250 | - | All | All | All |
| Operating System | Netapp | A250 Firmware | - | All | All | All |
| Hardware | Netapp | Baseboard Management Controller 500f | - | All | All | All |
| Operating System | Netapp | Baseboard Management Controller 500f Firmware | - | All | All | All |
| Hardware | Netapp | Baseboard Management Controller A250 | - | All | All | All |
| Operating System | Netapp | Baseboard Management Controller A250 Firmware | - | All | All | All |
| Hardware | Netapp | Baseboard Management Controller H410c | - | All | All | All |
| Operating System | Netapp | Baseboard Management Controller H410c Firmware | - | All | All | All |
| Hardware | Netapp | H410c | - | All | All | All |
| Operating System | Netapp | H410c Firmware | - | All | All | All |
| Operating System | Netapp | Hci Compute Node Bios | - | All | All | All |
| Application | Netapp | Solidfire Hci Management Node | - | All | All | All |
| Application | Netapp | Solidfire Hci Storage Node | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-29374 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] [DLA 2941-1] linux-4.19 security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 2689-1] linux security update | MLIST | lists.debian.org | |
| Kernel Live Patch Security Notice LSN-0075-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| 2045 - project-zero - Project Zero - Monorail | MISC | bugs.chromium.org | Exploit, Issue Tracking, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | Patch, Vendor Advisory |
| [SECURITY] [DLA 2690-1] linux-4.19 security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-5096-1 linux | DEBIAN | www.debian.org | |
| cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.3 | MISC | cdn.kernel.org | Release Notes, Third Party Advisory, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174764 SUSE Enterprise Linux Security update for the Linux Kernel (SUSE-SU-2021:0738-1)
- 174768 SUSE Enterprise Linux Security update for the Linux Kernel (SUSE-SU-2021:0735-1)
- 174770 SUSE Enterprise Linux Security update for the Linux Kernel (SUSE-SU-2021:0741-1)
- 174772 SUSE Enterprise Linux Security update for the Linux Kernel (SUSE-SU-2021:0737-1)
- 174774 SUSE Enterprise Linux Security update for the Linux Kernel (SUSE-SU-2021:0740-1)
- 174897 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1175-1)
- 174916 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:1210-1)
- 178679 Debian Security Update for linux-4.19 (DLA 2690-1)
- 178680 Debian Security Update for linux (DLA 2689-1)
- 179117 Debian Security Update for linux (DSA 5096-1)
- 179119 Debian Security Update for linux-4.19 (DLA 2941-1)
- 352366 Amazon Linux Security Advisory for kernel: ALAS-2021-1503
- 352375 Amazon Linux Security Advisory for kernel: ALAS2-2021-1636
- 353242 Amazon Linux Security Advisory for kernel : ALAC2012-2022-036
- 353243 Amazon Linux Security Advisory for kmod-mlx5 : ALAC2012-2022-037
- 353244 Amazon Linux Security Advisory for kmod-sfc : ALAC2012-2022-038
- 610500 Google Android Devices August 2023 Security Patch Missing
- 610519 Google Android November 2023 Security Patch Missing for Samsung
- 750324 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:0393-1)
- 900040 CBL-Mariner Linux Security Update for kernel 5.4.91
- 903215 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3623)
- 906126 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3623-1)