Input validation error in Linux kernel - CVE-2020-10768
Published: September 16, 2020 / Updated: September 24, 2020
Vulnerability details
The vulnerability allows a local authenticated user to gain access to sensitive information.
A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.
Affected software
Anolis OS
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Google Android
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Ubuntu
Fedora
kpatch-patch-4_18_0-147_20_1 (Red Hat package)
kpatch-patch-4_18_0-193_6_3 (Red Hat package)
kpatch-patch-4_18_0-147_13_2 (Red Hat package)
kpatch-patch-4_18_0-193_1_2 (Red Hat package)
kpatch-patch-4_18_0-193 (Red Hat package)
kpatch-patch-4_18_0-147_8_1 (Red Hat package)
kpatch-patch-4_18_0-147_5_1 (Red Hat package)
kpatch-patch-4_18_0-147_0_3 (Red Hat package)
kpatch-patch-4_18_0-147_0_2 (Red Hat package)
kpatch-patch-4_18_0-147_3_1 (Red Hat package)
kpatch-patch-4_18_0-147 (Red Hat package)
linux-image-generic-lpae (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-4.15.0-115-lowlatency (Ubuntu package)
linux-image-4.15.0-115-generic-lpae (Ubuntu package)
linux-image-4.15.0-115-generic (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-4.15.0-1051-oracle (Ubuntu package)
linux-image-oracle-lts-18.04 (Ubuntu package)
linux-image-4.15.0-1067-gke (Ubuntu package)
linux-image-gke-4.15 (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-raspi2 (Ubuntu package)
linux-image-4.15.0-1068-raspi2 (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-4.15.0-1072-kvm (Ubuntu package)
linux-image-aws-hwe (Ubuntu package)
linux-image-aws-lts-18.04 (Ubuntu package)
linux-image-4.15.0-1080-aws (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-4.15.0-1081-gcp (Ubuntu package)
linux-image-gcp-lts-18.04 (Ubuntu package)
linux-image-snapdragon (Ubuntu package)
linux-image-4.15.0-1084-snapdragon (Ubuntu package)
linux-image-azure-lts-18.04 (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-azure-edge (Ubuntu package)
linux-image-4.15.0-1093-azure (Ubuntu package)
linux-image-oem (Ubuntu package)
linux-image-4.15.0-1094-oem (Ubuntu package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
bpftool
perf
python-perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-headers
kernel-devel
kernel-debug-devel
kernel-debug
kernel
linux-image-oem-osp1 (Ubuntu package)
linux-image-5.4.0-45-generic (Ubuntu package)
linux-image-5.4.0-45-generic-lpae (Ubuntu package)
linux-image-5.4.0-45-lowlatency (Ubuntu package)
linux-image-generic-hwe-18.04 (Ubuntu package)
linux-image-generic-lpae-hwe-18.04 (Ubuntu package)
linux-image-gkeop-5.4 (Ubuntu package)
linux-image-lowlatency-hwe-18.04 (Ubuntu package)
linux-image-virtual-hwe-18.04 (Ubuntu package)
linux-image-snapdragon-hwe-18.04 (Ubuntu package)
linux-image-5.4.0-1016-raspi (Ubuntu package)
linux-image-raspi-hwe-18.04 (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-aws-edge (Ubuntu package)
linux-image-gke-5.4 (Ubuntu package)
linux-image-5.4.0-1022-oracle (Ubuntu package)
linux-image-5.4.0-1022-aws (Ubuntu package)
linux-image-5.4.0-1022-gcp (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-5.4.0-1023-azure (Ubuntu package)
How to mitigate CVE-2020-10768
Google Android - addressed in versions 8.1 2021-10-05, 9 2021-10-05, 10 2021-10-05, 11 2021-10-05
kpatch-patch-4_18_0-147_20_1 (Red Hat package) - update to 1-2.el8_1
kpatch-patch-4_18_0-193_6_3 (Red Hat package) - update to 1-2.el8_2
kpatch-patch-4_18_0-147_13_2 (Red Hat package) - update to 1-3.el8_1
kpatch-patch-4_18_0-193_1_2 (Red Hat package) - update to 1-3.el8_2
kpatch-patch-4_18_0-193 (Red Hat package) - update to 1-5.el8
kpatch-patch-4_18_0-147_8_1 (Red Hat package) - update to 1-5.el8_1
kpatch-patch-4_18_0-147_5_1 (Red Hat package) - update to 1-7.el8_1
kpatch-patch-4_18_0-147_0_3 (Red Hat package) - update to 1-12.el8
kpatch-patch-4_18_0-147_0_2 (Red Hat package) - update to 1-12.el8
kpatch-patch-4_18_0-147_3_1 (Red Hat package) - update to 1-12.el8_1
kpatch-patch-4_18_0-147 (Red Hat package) - update to 1-16.el8
linux-image-generic-lpae (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-lowlatency (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-generic (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-virtual (Ubuntu package) - addressed in versions 4.15.0.115.103, 5.4.0.45.49
linux-image-4.15.0-115-lowlatency (Ubuntu package) - update to 4.15.0-115.116~16.04.1
linux-image-4.15.0-115-generic-lpae (Ubuntu package) - update to 4.15.0-115.116~16.04.1
linux-image-4.15.0-115-generic (Ubuntu package) - update to 4.15.0-115.116~16.04.1
linux-image-oracle (Ubuntu package) - addressed in versions 4.15.0.1051.42, 5.4.0.1022.7, 5.4.0.1022.20
linux-image-4.15.0-1051-oracle (Ubuntu package) - addressed in versions 4.15.0-1051.55, 4.15.0-1051.55~16.04.1
linux-image-oracle-lts-18.04 (Ubuntu package) - update to 4.15.0.1051.62
linux-image-4.15.0-1067-gke (Ubuntu package) - update to 4.15.0-1067.70
linux-image-gke-4.15 (Ubuntu package) - update to 4.15.0.1067.71
linux-image-gke (Ubuntu package) - addressed in versions 4.15.0.1067.71, 4.15.0.1081.83, 5.4.0.1022.20
linux-image-raspi2 (Ubuntu package) - addressed in versions 4.15.0.1068.66, 5.4.0.1016.51
linux-image-4.15.0-1068-raspi2 (Ubuntu package) - update to 4.15.0-1068.72
linux-image-kvm (Ubuntu package) - addressed in versions 4.15.0.1072.68, 5.4.0.1021.20
linux-image-4.15.0-1072-kvm (Ubuntu package) - update to 4.15.0-1072.73
linux-image-aws-hwe (Ubuntu package) - update to 4.15.0.1080.77
linux-image-aws-lts-18.04 (Ubuntu package) - update to 4.15.0.1080.82
linux-image-4.15.0-1080-aws (Ubuntu package) - addressed in versions 4.15.0-1080.84, 4.15.0-1080.84~16.04.1
linux-image-gcp (Ubuntu package) - addressed in versions 4.15.0.1081.83, 5.4.0.1022.9, 5.4.0.1022.20
linux-image-4.15.0-1081-gcp (Ubuntu package) - addressed in versions 4.15.0-1081.92, 4.15.0-1081.92~16.04.1
linux-image-gcp-lts-18.04 (Ubuntu package) - update to 4.15.0.1081.99
linux-image-snapdragon (Ubuntu package) - update to 4.15.0.1084.87
linux-image-4.15.0-1084-snapdragon (Ubuntu package) - update to 4.15.0-1084.92
linux-image-azure-lts-18.04 (Ubuntu package) - update to 4.15.0.1093.67
linux-image-azure (Ubuntu package) - addressed in versions 4.15.0.1093.70, 4.15.0.1093.88, 5.4.0.1023.7, 5.4.0.1023.22
linux-image-azure-edge (Ubuntu package) - update to 4.15.0.1093.88
linux-image-4.15.0-1093-azure (Ubuntu package) - addressed in versions 4.15.0-1093.103, 4.15.0-1093.103~14.04.1, 4.15.0-1093.103~16.04.1
linux-image-oem (Ubuntu package) - addressed in versions 4.15.0.1094.98, 5.4.0.45.49
linux-image-4.15.0-1094-oem (Ubuntu package) - update to 4.15.0-1094.104
kernel (Red Hat package) - addressed in versions 4.18.0-80.27.1.el8_0, 4.18.0-147.24.2.el8_1, 4.18.0-193.13.2.el8_2
kernel-rt (Red Hat package) - update to 4.18.0-193.13.2.rt13.65.el8_2
bpftool - update to 4.19.91-26
perf - update to 4.19.91-26
python-perf - update to 4.19.91-26
kernel-tools-libs-devel - update to 4.19.91-26
kernel-tools-libs - update to 4.19.91-26
kernel-tools - update to 4.19.91-26
kernel-headers - update to 4.19.91-26
kernel-devel - update to 4.19.91-26
kernel-debug-devel - update to 4.19.91-26
kernel-debug - update to 4.19.91-26
kernel - update to 4.19.91-26
linux-image-oem-osp1 (Ubuntu package) - update to 5.4.0.45.49
linux-image-5.4.0-45-generic (Ubuntu package) - update to 5.4.0-45.49~18.04.2
linux-image-5.4.0-45-generic-lpae (Ubuntu package) - update to 5.4.0-45.49~18.04.2
linux-image-5.4.0-45-lowlatency (Ubuntu package) - update to 5.4.0-45.49~18.04.2
linux-image-generic-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-generic-lpae-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-gkeop-5.4 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-lowlatency-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-virtual-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-snapdragon-hwe-18.04 (Ubuntu package) - update to 5.4.0.45.49~18.04.38
linux-image-5.4.0-1016-raspi (Ubuntu package) - update to 5.4.0-1016.17~18.04.1
linux-image-raspi-hwe-18.04 (Ubuntu package) - update to 5.4.0.1016.20
linux-image-raspi (Ubuntu package) - update to 5.4.0.1016.51
linux-image-aws-edge (Ubuntu package) - update to 5.4.0.1022.8
linux-image-gke-5.4 (Ubuntu package) - update to 5.4.0.1022.9
linux-image-5.4.0-1022-oracle (Ubuntu package) - update to 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1022-aws (Ubuntu package) - update to 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1022-gcp (Ubuntu package) - update to 5.4.0-1022.22~18.04.1
linux-image-aws (Ubuntu package) - update to 5.4.0.1022.23
linux-image-5.4.0-1023-azure (Ubuntu package) - update to 5.4.0-1023.23~18.04.1
kernel - addressed in versions 5.6.19-200.fc31, 5.6.19-300.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Android
- Red Hat Enterprise Linux 8 update for kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions update for kernel
- Red Hat Enterprise Linux 8 update for kpatch-patch
- Red Hat Enterprise Linux 8.1 Extended Update Support update for kernel
- Red Hat Enterprise Linux 8.1 Extended Update Support update for kpatch-patch
- Anolis OS update for kernel(ANCK)4.19
- Ubuntu update for linux
- Ubuntu update for linux
- Fedora 32 update for kernel
- Fedora 31 update for kernel