CVE-2020-10773
published 2020-09-10CVE-2020-10773: A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the…
PriorityP418medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.37%
29.4th percentile
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.3.9-1 (bookworm) | linux 5.3.9-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.3.9-1 | 5.3.9-1 |
| linux | linux_kernel | >= 0 < 5.3.9-1 | 5.3.9-1 |
| linux | linux_kernel | >= 0 < 5.3.9-1 | 5.3.9-1 |
| linux | linux_kernel | >= 0 < 5.3.9-1 | 5.3.9-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3wp9-9gg6-rwqx: A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys
ghsa_unreviewed·2022-05-24
CVE-2020-10773 [LOW] GHSA-3wp9-9gg6-rwqx: A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
OSV
CVE-2020-10773: A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys
osv·2020-09-10·CVSS 4.4
CVE-2020-10773 [MEDIUM] CVE-2020-10773: A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
Debian
CVE-2020-10773: linux - A stack information leak flaw was found in s390/s390x in the Linux kernel’s memo...
vendor_debian·2020·CVSS 4.4
CVE-2020-10773 [MEDIUM] CVE-2020-10773: linux - A stack information leak flaw was found in s390/s390x in the Linux kernel’s memo...
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
Scope: local
bookworm: resolved (fixed in 5.3.9-1)
bullseye: resolved (fixed in 5.3.9-1)
forky: resolved (fixed in 5.3.9-1)
sid: resolved (fixed in 5.3.9-1)
trixie: resolved (fixed in 5.3.9-1)
Red Hat
kernel: kernel stack information leak on s390/s390x
vendor_redhat·2019-10-28·CVSS 4.4
CVE-2020-10773 [MEDIUM] CWE-626 kernel: kernel stack information leak on s390/s390x
kernel: kernel stack information leak on s390/s390x
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
Statement: This issue is rated as having Low impact because of being limited to only s390 architecture and very limited kernel stack exposure.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria co
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10773 kernel: kernel stack information leak on s390/s390x [fedora-all]
bugzilla·2020-06-11·CVSS 4.4
CVE-2020-10773 [MEDIUM] CVE-2020-10773 kernel: kernel stack information leak on s390/s390x [fedora-all]
CVE-2020-10773 kernel: kernel stack information leak on s390/s390x [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2020-10773 kernel: kernel stack information leak on s390/s390x
bugzilla·2020-06-11·CVSS 4.4
CVE-2020-10773 [MEDIUM] CVE-2020-10773 kernel: kernel stack information leak on s390/s390x
CVE-2020-10773 kernel: kernel stack information leak on s390/s390x
In function cmm_timeout_hander in file arch/s390/mm/cmm.c, there is a logic error which set null byte too far away from user input which means user input won't be null terminated. And then, kernel stack data will be concatenated with user input and be processed. By querying the result, attacker is able to see the kernel data.
This is linux kernel stack information leak on s390/s390x (and it is actual both for s390, ppc64 and ppc64le platforms).
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1846531]
---
Mitigation:
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployme
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10773https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b8e51a6a9db94bc1fb18ae831b3dab106b5a4b5fhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10773https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b8e51a6a9db94bc1fb18ae831b3dab106b5a4b5f
2020-09-10
Published