Race condition in Linux kernel - CVE-2020-11884
Published: April 29, 2020 / Updated: June 1, 2020
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
In the Linux kernel through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Fedora
kernel (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
kernel
How to mitigate CVE-2020-11884
kernel (Red Hat package) - addressed in versions 4.18.0-80.23.2.el8_0, 4.18.0-147.13.2.el8_1, 4.18.0-193.1.2.el8_2
kernel - addressed in versions 5.6.8-100.fc30, 5.6.8-200.fc31, 5.6.8-300.fc32