cbcvebase.
CVE-2020-25285
published 2020-09-13

CVE-2020-25285: A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a…

PriorityP423medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.27%
19.4th percentile
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.8.10-1 (bookworm)linux 5.8.10-1 (bookworm)
linuxlinux_kernel< 5.8.85.8.8
linuxlinux_kernel>= 0 < 5.8.10-15.8.10-1
linuxlinux_kernel>= 0 < 5.8.10-15.8.10-1
linuxlinux_kernel>= 0 < 5.8.10-15.8.10-1
linuxlinux_kernel>= 0 < 5.8.10-15.8.10-1
linuxlinux_kernel>= 0 < 4.4.0-193.2244.4.0-193.224
linuxlinux_kernel>= 0 < 4.15.0-128.1314.15.0-128.131
linuxlinux_kernel>= 0 < 4.15.0-126.1294.15.0-126.129
linuxlinux_kernel>= 0 < 5.4.0-51.565.4.0-51.56
msrccm1_kernel_5.4.91-3_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.4MEDIUM
vendor_msrc6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.