Vulnerabilities > CVE-2020-29374 - Incorrect Authorization vulnerability in multiple products

047910
CVSS 3.6 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
local
high complexity
linux
debian
netapp
CWE-863

Summary

An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.

Vulnerable Configurations

Part Description Count
OS
Linux
4547
OS
Debian
2
OS
Netapp
4
Hardware
Netapp
3
Application
Netapp
2

Common Weakness Enumeration (CWE)