CVE-2020-10742
published 2021-06-02CVE-2020-10742: A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the…
PriorityP426medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.26%
17.8th percentile
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.2-2 (bookworm) | linux 3.16.2-2 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gvv-jxrj-2xcq: A flaw was found in the Linux kernel
ghsa_unreviewed·2022-05-24
CVE-2020-10742 [MEDIUM] CWE-787 GHSA-9gvv-jxrj-2xcq: A flaw was found in the Linux kernel
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
OSV
CVE-2020-10742: A flaw was found in the Linux kernel
osv·2021-06-02·CVSS 6.0
CVE-2020-10742 [MEDIUM] CVE-2020-10742: A flaw was found in the Linux kernel
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
Kernel
fortify: Detect struct member overflows in memcpy() at compile-time
kernel_security·2021-04-20
CVE-2019-0145 fortify: Detect struct member overflows in memcpy() at compile-time
fortify: Detect struct member overflows in memcpy() at compile-time
memcpy() is dead; long live memcpy()
tl;dr: In order to eliminate a large class of common buffer overflow
flaws that continue to persist in the kernel, have memcpy() (under
CONFIG_FORTIFY_SOURCE) perform bounds checking of the destination struct
member when they have a known size. This would have caught all of the
memcpy()-related buffer write overflow flaws identified in at least the
last three years.
Background and analysis:
While stack-based buffer overflow flaws are largely mitigated by stack
canaries (and similar) features, heap-based buffer overflow flaws continue
to regularly appear in the kernel. Many classes of heap buffer overflows
are mitigated by FORTIFY_SOURCE when using the strcpy() family of
functions, b
Red Hat
kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic
vendor_redhat·2020-05-13·CVSS 6.0
CVE-2020-10742 [MEDIUM] CWE-787 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic
kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
Package: kernel (Red Hat Enterprise Linux 5) - Not af
Debian
CVE-2020-10742: linux - A flaw was found in the Linux kernel. An index buffer overflow during Direct IO ...
vendor_debian·2020·CVSS 6.0
CVE-2020-10742 [MEDIUM] CVE-2020-10742: linux - A flaw was found in the Linux kernel. An index buffer overflow during Direct IO ...
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
Scope: local
bookworm: resolved (fixed in 3.16.2-2)
bullseye: resolved (fixed in 3.16.2-2)
forky: resolved (fixed in 3.16.2-2)
sid: resolved (fixed in 3.16.2-2)
trixie: resolved (fixed in 3.16.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic [fedora-all]
bugzilla·2020-05-13·CVSS 6.0
CVE-2020-10742 [MEDIUM] CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic [fedora-all]
CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic
bugzilla·2020-05-13·CVSS 6.0
CVE-2020-10742 [MEDIUM] CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic
CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic
NFS client crashes due to index buffer overflow during Direct IO write. In some circumstances, it reaches out of the index after just one memory allocation by kmalloc which is causing kernel panic at random function. (sub_debug shows Redzone is overwritten)
Upstream Issue:
https://bugzilla.redhat.com/show_bug.cgi?id=1824270
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1835128]
---
Hi Marian,
I'm trying to track this issue for Debian, and looked as well up https://bugzilla.redhat.com/show_bug.cgi?id=1824270. Do you have any additional information on this issue: Did it ever affected mainline/upstream or is the issue specific to the Red
Bugzilla
CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic [rhel-7]
bugzilla·2020-04-15·CVSS 6.0
CVE-2020-10742 [MEDIUM] CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic [rhel-7]
CVE-2020-10742 kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic [rhel-7]
Description of problem:
NFS client system will crash if the nfs4 session fore channel max_rqst_size returned by the server includes an overhead that is smaller than the client overhead.
Version-Release number of selected component (if applicable):
kernel 3.10.0-1062.1.1.el7.x86_64
kernel-3.10.0-957.46.1.el7.x86_64
kernel 3.10.0-862.9.1.el7.x86_64
How reproducible:
easy, see steps below
Steps to Reproduce:
nfs client and server can be the same system
# systemctl stop nfs-server.service
# echo 524288 > /proc/fs/nfsd/max_block_size
# systemctl start nfs-server.service
cat /var/tmp/limit_rwsize.stp
probe module("nfsd").function("check_forechannel_attrs") {
prin
2021-06-02
Published