Race condition in Linux kernel - CVE-2020-10766

 

Race condition in Linux kernel - CVE-2020-10766

Published: September 16, 2020 / Updated: September 26, 2020


Vulnerability identifier: #VU47074
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10766
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching.


Affected software

Linux kernel
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Ubuntu
Fedora
kpatch-patch-4_18_0-147_20_1 (Red Hat package)
kpatch-patch-4_18_0-193_6_3 (Red Hat package)
kpatch-patch-4_18_0-147_13_2 (Red Hat package)
kpatch-patch-4_18_0-193_1_2 (Red Hat package)
kpatch-patch-4_18_0-193 (Red Hat package)
kpatch-patch-4_18_0-147_8_1 (Red Hat package)
kpatch-patch-4_18_0-147_5_1 (Red Hat package)
kpatch-patch-4_18_0-147_0_2 (Red Hat package)
kpatch-patch-4_18_0-147_0_3 (Red Hat package)
kpatch-patch-4_18_0-147_3_1 (Red Hat package)
kpatch-patch-4_18_0-147 (Red Hat package)
linux-image-virtual (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-4.15.0-115-generic (Ubuntu package)
linux-image-4.15.0-115-generic-lpae (Ubuntu package)
linux-image-4.15.0-115-lowlatency (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-4.15.0-1051-oracle (Ubuntu package)
linux-image-oracle-lts-18.04 (Ubuntu package)
linux-image-4.15.0-1067-gke (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-gke-4.15 (Ubuntu package)
linux-image-raspi2 (Ubuntu package)
linux-image-4.15.0-1068-raspi2 (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-4.15.0-1072-kvm (Ubuntu package)
linux-image-aws-hwe (Ubuntu package)
linux-image-aws-lts-18.04 (Ubuntu package)
linux-image-4.15.0-1080-aws (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-4.15.0-1081-gcp (Ubuntu package)
linux-image-gcp-lts-18.04 (Ubuntu package)
linux-image-snapdragon (Ubuntu package)
linux-image-4.15.0-1084-snapdragon (Ubuntu package)
linux-image-azure-lts-18.04 (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-azure-edge (Ubuntu package)
linux-image-4.15.0-1093-azure (Ubuntu package)
linux-image-oem (Ubuntu package)
linux-image-4.15.0-1094-oem (Ubuntu package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
bpftool
kernel-debug-devel
kernel
kernel-debug
kernel-devel
kernel-headers
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python-perf
linux-image-oem-osp1 (Ubuntu package)
linux-image-5.4.0-45-lowlatency (Ubuntu package)
linux-image-5.4.0-45-generic-lpae (Ubuntu package)
linux-image-5.4.0-45-generic (Ubuntu package)
linux-image-snapdragon-hwe-18.04 (Ubuntu package)
linux-image-virtual-hwe-18.04 (Ubuntu package)
linux-image-generic-hwe-18.04 (Ubuntu package)
linux-image-generic-lpae-hwe-18.04 (Ubuntu package)
linux-image-gkeop-5.4 (Ubuntu package)
linux-image-lowlatency-hwe-18.04 (Ubuntu package)
linux-image-5.4.0-1016-raspi (Ubuntu package)
linux-image-raspi-hwe-18.04 (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-aws-edge (Ubuntu package)
linux-image-gke-5.4 (Ubuntu package)
linux-image-5.4.0-1022-oracle (Ubuntu package)
linux-image-5.4.0-1022-gcp (Ubuntu package)
linux-image-5.4.0-1022-aws (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-5.4.0-1023-azure (Ubuntu package)

How to mitigate CVE-2020-10766

Install update from vendor's website.

Linux kernel - update to 5.8.0
kpatch-patch-4_18_0-147_20_1 (Red Hat package) - update to 1-2.el8_1
kpatch-patch-4_18_0-193_6_3 (Red Hat package) - update to 1-2.el8_2
kpatch-patch-4_18_0-147_13_2 (Red Hat package) - update to 1-3.el8_1
kpatch-patch-4_18_0-193_1_2 (Red Hat package) - update to 1-3.el8_2
kpatch-patch-4_18_0-193 (Red Hat package) - update to 1-5.el8
kpatch-patch-4_18_0-147_8_1 (Red Hat package) - update to 1-5.el8_1
kpatch-patch-4_18_0-147_5_1 (Red Hat package) - update to 1-7.el8_1
kpatch-patch-4_18_0-147_0_2 (Red Hat package) - update to 1-12.el8
kpatch-patch-4_18_0-147_0_3 (Red Hat package) - update to 1-12.el8
kpatch-patch-4_18_0-147_3_1 (Red Hat package) - update to 1-12.el8_1
kpatch-patch-4_18_0-147 (Red Hat package) - update to 1-16.el8
linux-image-virtual (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-lowlatency (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-generic-lpae (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-generic (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-4.15.0-115-generic (Ubuntu package) - update to 4.15.0-115.116~16.04.1
linux-image-4.15.0-115-generic-lpae (Ubuntu package) - update to 4.15.0-115.116~16.04.1
linux-image-4.15.0-115-lowlatency (Ubuntu package) - update to 4.15.0-115.116~16.04.1
linux-image-oracle (Ubuntu package) - addressed in versions 4.15.0.1051.42, 5.4.0.1022.7, 5.4.0.1022.20
linux-image-4.15.0-1051-oracle (Ubuntu package) - addressed in versions 4.15.0-1051.55, 4.15.0-1051.55~16.04.1
linux-image-oracle-lts-18.04 (Ubuntu package) - update to 4.15.0.1051.62
linux-image-4.15.0-1067-gke (Ubuntu package) - update to 4.15.0-1067.70
linux-image-gke (Ubuntu package) - addressed in versions 4.15.0.1067.71, 4.15.0.1081.83, 5.4.0.1022.20
linux-image-gke-4.15 (Ubuntu package) - update to 4.15.0.1067.71
linux-image-raspi2 (Ubuntu package) - addressed in versions 4.15.0.1068.66, 5.4.0.1016.51
linux-image-4.15.0-1068-raspi2 (Ubuntu package) - update to 4.15.0-1068.72
linux-image-kvm (Ubuntu package) - addressed in versions 4.15.0.1072.68, 5.4.0.1021.20
linux-image-4.15.0-1072-kvm (Ubuntu package) - update to 4.15.0-1072.73
linux-image-aws-hwe (Ubuntu package) - update to 4.15.0.1080.77
linux-image-aws-lts-18.04 (Ubuntu package) - update to 4.15.0.1080.82
linux-image-4.15.0-1080-aws (Ubuntu package) - addressed in versions 4.15.0-1080.84, 4.15.0-1080.84~16.04.1
linux-image-gcp (Ubuntu package) - addressed in versions 4.15.0.1081.83, 5.4.0.1022.9, 5.4.0.1022.20
linux-image-4.15.0-1081-gcp (Ubuntu package) - addressed in versions 4.15.0-1081.92, 4.15.0-1081.92~16.04.1
linux-image-gcp-lts-18.04 (Ubuntu package) - update to 4.15.0.1081.99
linux-image-snapdragon (Ubuntu package) - update to 4.15.0.1084.87
linux-image-4.15.0-1084-snapdragon (Ubuntu package) - update to 4.15.0-1084.92
linux-image-azure-lts-18.04 (Ubuntu package) - update to 4.15.0.1093.67
linux-image-azure (Ubuntu package) - addressed in versions 4.15.0.1093.70, 4.15.0.1093.88, 5.4.0.1023.7, 5.4.0.1023.22
linux-image-azure-edge (Ubuntu package) - update to 4.15.0.1093.88
linux-image-4.15.0-1093-azure (Ubuntu package) - addressed in versions 4.15.0-1093.103, 4.15.0-1093.103~14.04.1, 4.15.0-1093.103~16.04.1
linux-image-oem (Ubuntu package) - addressed in versions 4.15.0.1094.98, 5.4.0.45.49
linux-image-4.15.0-1094-oem (Ubuntu package) - update to 4.15.0-1094.104
kernel (Red Hat package) - addressed in versions 4.18.0-80.27.1.el8_0, 4.18.0-147.24.2.el8_1, 4.18.0-193.13.2.el8_2
kernel-rt (Red Hat package) - update to 4.18.0-193.13.2.rt13.65.el8_2
bpftool - update to 4.19.91-26
kernel-debug-devel - update to 4.19.91-26
kernel - update to 4.19.91-26
kernel-debug - update to 4.19.91-26
kernel-devel - update to 4.19.91-26
kernel-headers - update to 4.19.91-26
kernel-tools - update to 4.19.91-26
kernel-tools-libs - update to 4.19.91-26
kernel-tools-libs-devel - update to 4.19.91-26
perf - update to 4.19.91-26
python-perf - update to 4.19.91-26
linux-image-oem-osp1 (Ubuntu package) - update to 5.4.0.45.49
linux-image-5.4.0-45-lowlatency (Ubuntu package) - update to 5.4.0-45.49~18.04.2
linux-image-5.4.0-45-generic-lpae (Ubuntu package) - update to 5.4.0-45.49~18.04.2
linux-image-5.4.0-45-generic (Ubuntu package) - update to 5.4.0-45.49~18.04.2
linux-image-snapdragon-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-virtual-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-generic-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-generic-lpae-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-gkeop-5.4 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-lowlatency-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-5.4.0-1016-raspi (Ubuntu package) - update to 5.4.0-1016.17~18.04.1
linux-image-raspi-hwe-18.04 (Ubuntu package) - update to 5.4.0.1016.20
linux-image-raspi (Ubuntu package) - update to 5.4.0.1016.51
linux-image-aws-edge (Ubuntu package) - update to 5.4.0.1022.8
linux-image-gke-5.4 (Ubuntu package) - update to 5.4.0.1022.9
linux-image-5.4.0-1022-oracle (Ubuntu package) - update to 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1022-gcp (Ubuntu package) - update to 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1022-aws (Ubuntu package) - update to 5.4.0-1022.22~18.04.1
linux-image-aws (Ubuntu package) - update to 5.4.0.1022.23
linux-image-5.4.0-1023-azure (Ubuntu package) - update to 5.4.0-1023.23~18.04.1
kernel - addressed in versions 5.6.19-200.fc31, 5.6.19-300.fc32

External References

Related Security Bulletins