ShaikUsaf / linux-4.19.72_CVE-2020-10757

Other
0 stars 0 forks source link

CVE-2020-11565 (Medium) detected in linuxlinux-4.19.236 #310

Open mend-bolt-for-github[bot] opened 2 years ago

mend-bolt-for-github[bot] commented 2 years ago

CVE-2020-11565 - Medium Severity Vulnerability

Vulnerable Library - linuxlinux-4.19.236

The Linux Kernel

Library home page: https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/?wsslib=linux

Found in HEAD commit: 63ec46be94f7d206b296bb6c7cd636df4b2eaddd

Found in base branch: master

Vulnerable Source Files (1)

/mm/mempolicy.c

Vulnerability Details

** DISPUTED ** An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community disagrees that this is a vulnerability because the issue “is a bug in parsing mount options which can only be specified by a privileged user, so triggering the bug does not grant any powers not already held.”.

Publish Date: 2020-04-06

URL: CVE-2020-11565

CVSS 3 Score Details (6.0)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: High - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.linuxkernelcves.com/cves/CVE-2020-11565

Release Date: 2020-06-10

Fix Resolution: v5.7-rc1,v3.16.83,v4.14.176,v4.19.115,v4.4.219,v4.9.219,v5.4.31,v5.5.16,v5.6.3


Step up your Open Source Security Game with Mend here