CVE-2020-25641Infinite Loop in Kernel

CWE-835Infinite Loop12 documents9 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 24

Description

A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 5.8.10-1+3
NVDlinux/linux_kernel5.8.13+1
CVEListV5linux/linux_kernelkernel versions before 5.9-rc7
NVDopensuse/leap15.1, 15.2+1

Also affects: Enterprise Linux 7.0, 8.0, Debian Linux 9.0, Ubuntu Linux 18.04, 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8c9g-77vh-m2jv: A flaw was found in the Linux kernel's implementation of biovecs in versions before 52022-05-24
CVEList
CVE-2020-25641: A flaw was found in the Linux kernel's implementation of biovecs in versions before 52020-10-06
OSV
CVE-2020-25641: A flaw was found in the Linux kernel's implementation of biovecs in versions before 52020-10-06

📋Vendor Advisories

6
Ubuntu
Linux kernel (OEM) vulnerabilities2021-02-25
Ubuntu
Linux kernel vulnerabilities2020-12-03
Ubuntu
Linux kernel vulnerabilities2020-10-14
Microsoft
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop2020-10-13
Red Hat
kernel: soft-lockups in iov_iter_copy_from_user_atomic() could result in DoS2020-09-30

💬Community

2
Bugzilla
CVE-2020-25641 kernel: soft-lockups in iov_iter_copy_from_user_atomic() could result in DoS [fedora-all]2020-09-30
Bugzilla
CVE-2020-25641 kernel: soft-lockups in iov_iter_copy_from_user_atomic() could result in DoS2020-09-22
CVE-2020-25641 — Infinite Loop in Linux Kernel | cvebase