{"api_version":"1","generated_at":"2026-07-24T22:13:32+00:00","cve":"CVE-2020-25221","urls":{"html":"https://cve.report/CVE-2020-25221","api":"https://cve.report/api/cve/CVE-2020-25221.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-25221","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-25221"},"summary":{"title":"CVE-2020-25221","description":"get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-09-10 14:15:00","updated_at":"2023-02-02 22:23:00"},"problem_types":["CWE-672"],"metrics":[],"references":[{"url":"https://security.netapp.com/advisory/ntap-20201001-0003/","name":"https://security.netapp.com/advisory/ntap-20201001-0003/","refsource":"CONFIRM","tags":[],"title":"CVE-2020-25221 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://git.kernel.org/linus/9fa2dd946743ae6f30dc4830da19147bf100a7f2","name":"https://git.kernel.org/linus/9fa2dd946743ae6f30dc4830da19147bf100a7f2","refsource":"MISC","tags":["Issue Tracking","Patch","Vendor Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2020/09/08/4","name":"https://www.openwall.com/lists/oss-security/2020/09/08/4","refsource":"MISC","tags":["Mailing List","Patch","Third Party Advisory"],"title":"oss-security - CVE Request: Linux kernel vsyscall page refcounting error","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2020/09/10/4","name":"[oss-security] 20200910 Re: CVE Request: Linux kernel vsyscall page refcounting error","refsource":"MLIST","tags":["Third Party Advisory"],"title":"oss-security - Re: CVE Request: Linux kernel vsyscall page\n refcounting error","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.7","name":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.7","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://git.kernel.org/linus/8891adc61dce2a8a41fc0c23262b681c3ec4b73a","name":"https://git.kernel.org/linus/8891adc61dce2a8a41fc0c23262b681c3ec4b73a","refsource":"MISC","tags":["Issue Tracking","Patch","Vendor Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-25221","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25221","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"cloud_backup","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"netapp","cpe5":"hci_compute_node","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"solidfire\\,_enterprise_sds_\\&_hci_storage_node","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"netapp","cpe5":"solidfire_baseboard_management_controller","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"solidfire_\\&_hci_management_node","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-25221","qid":"180677","title":"Debian Security Update for linux (CVE-2020-25221)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-25221","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.openwall.com/lists/oss-security/2020/09/08/4","refsource":"MISC","name":"https://www.openwall.com/lists/oss-security/2020/09/08/4"},{"url":"https://git.kernel.org/linus/9fa2dd946743ae6f30dc4830da19147bf100a7f2","refsource":"MISC","name":"https://git.kernel.org/linus/9fa2dd946743ae6f30dc4830da19147bf100a7f2"},{"url":"https://git.kernel.org/linus/8891adc61dce2a8a41fc0c23262b681c3ec4b73a","refsource":"MISC","name":"https://git.kernel.org/linus/8891adc61dce2a8a41fc0c23262b681c3ec4b73a"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.7","refsource":"MISC","name":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.7"},{"refsource":"MLIST","name":"[oss-security] 20200910 Re: CVE Request: Linux kernel vsyscall page refcounting error","url":"http://www.openwall.com/lists/oss-security/2020/09/10/4"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20201001-0003/","url":"https://security.netapp.com/advisory/ntap-20201001-0003/"}]}},"nvd":{"publishedDate":"2020-09-10 14:15:00","lastModifiedDate":"2023-02-02 22:23:00","problem_types":["CWE-672"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7.0","versionEndExcluding":"5.8.7","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:solidfire_\\&_hci_management_node:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:solidfire\\,_enterprise_sds_\\&_hci_storage_node:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"25221","Ordinal":"186632","Title":"CVE-2020-25221","CVE":"CVE-2020-25221","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"25221","Ordinal":"1","NoteData":"get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"25221","Ordinal":"2","NoteData":"2020-09-10","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"25221","Ordinal":"3","NoteData":"2020-10-01","Type":"Other","Title":"Modified"}]}}}