CVE-2020-29374: Race Condition
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/hugememory.c. The getuserpages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-4369
- CVE-2023-20593
- CVE-2023-4211
- CVE-2023-4128
- CVE-2023-4147
- CVE-2023-3390
- CVE-2023-32804
- CVE-2022-40982
- CVE-2023-2312
- CVE-2023-4349
- CVE-2023-4350
- CVE-2023-4351
- CVE-2023-4352
- CVE-2023-4353
- CVE-2023-4354
- CVE-2023-4355
- CVE-2023-4356
- CVE-2023-4357
- CVE-2023-4358
- CVE-2023-4359
- CVE-2023-4360
- CVE-2023-4361
- CVE-2023-4362
- CVE-2023-4363
- CVE-2023-4364
- CVE-2023-4365
- CVE-2023-4366
- CVE-2023-4367
- CVE-2023-4368
- CVE-2023-21264
Frequently Asked Questions
What is the severity of CVE-2020-29374?
CVE-2020-29374 has been classified with a high severity due to potential unauthorized write access in the Linux kernel.
How do I fix CVE-2020-29374?
To remediate CVE-2020-29374, update your Linux kernel to version 5.7.3 or later.
Which versions of the Linux kernel are affected by CVE-2020-29374?
CVE-2020-29374 affects Linux kernel versions before 5.7.3.
What systems are impacted by CVE-2020-29374?
CVE-2020-29374 impacts various operating systems including older versions of Debian and Android that utilize the vulnerable Linux kernel.
What are the potential consequences of CVE-2020-29374 if exploited?
Exploitation of CVE-2020-29374 could allow an attacker to gain unintended write access to memory pages, leading to data corruption or system compromise.