Buffer overflow in Linux kernel - CVE-2020-10742
Published: June 2, 2022
Vulnerability identifier: #VU63957
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10742
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an index buffer overflow during Direct IO write in NFS client. A local user can force the client to reach out of the index after one memory allocation by kmalloc and cause a kernel panic.
Affected software
Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Workstation
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Workstation
kernel (Red Hat package)
kernel-rt (Red Hat package)
How to mitigate CVE-2020-10742
Install updates from vendor's website.
kernel (Red Hat package) - update to 3.10.0-1160.el7
kernel-rt (Red Hat package) - update to 3.10.0-1160.rt56.1131.el7
kernel-rt (Red Hat package) - update to 3.10.0-1160.rt56.1131.el7