CVE-2020-29370Race Condition in Kernel

CWE-362Race Condition7 documents7 sources
Severity
7.0HIGHNVD
EPSS
0.4%
top 41.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 28
Latest updateMay 24

Description

An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel< 5.5.11
Debianlinux/linux_kernel< 5.5.13-1+3
debiandebian/linux< linux 5.5.13-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3qvh-h66j-93ff: An issue was discovered in kmem_cache_alloc_bulk in mm/slub2022-05-24
OSV
CVE-2020-29370: An issue was discovered in kmem_cache_alloc_bulk in mm/slub2020-11-28

📋Vendor Advisories

3
Microsoft
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment aka CID-fd4d9c7d0c71.2020-11-10
Red Hat
kernel: Race condition in SLUB bulk alloc slowpath2020-06-15
Debian
CVE-2020-29370: linux - An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kerne...2020

💬Community

1
Bugzilla
CVE-2020-29370 kernel: Race condition in SLUB bulk alloc slowpath2020-09-04