CVE-2020-11565 PUBLISHED

An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community disagrees that this is a vulnerability because the issue “is a bug in parsing mount options which can only be specified by a privileged user, so triggering the bug does not grant any powers not already held.”

EPSS 0.08% · 24.2th percentile

Risk Scores

EPSS Score
0.08%
24.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux4.4.0-127.153, 4.4.0-131.157, 4.4.0-130.156
Ubuntu:20.04:LTSlinux-gcp5.4.0-1009.9, 5.4.0-1005.5, 0
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:18.04:LTSlinux-gcp4.15.0-1019.20, 4.15.0-1015.15, 4.15.0-1003.3
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1065.69~16.04.1, 4.15.0-1066.70~16.04.1, *
Ubuntu:16.04:LTSlinux-aws4.4.0-1047.56, 4.4.0-1038.47, 4.4.0-1095.106
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips4.15.0-1002.2, 0
Ubuntu:18.04:LTSlinux-gcp-edge0, *, 5.0.0-1013.13~18.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1085.90+cvm2.1, 5.4.0-1086.91+cvm1.1, 5.4.0-1089.94+cvm1.2
Ubuntu:16.04:LTSlinux-oracle4.15.0-1007.9~16.04.1, 0, 4.15.0-1008.10~16.04.1
Ubuntu:18.04:LTSlinux-oracle-5.35.3.0-1014.15~18.04.1, 0, 5.3.0-1011.12~18.04.1
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1039.41~14.04.2, 4.15.0-1035.36~14.04.2, 4.15.0-1032.33~14.04.2
Ubuntu:18.04:LTSlinux-aws4.15.0-1051.53, 4.15.0-1045.47, 4.15.0-1039.41
Ubuntu:18.04:LTSlinux-oem-osp15.0.0-1037.42, 5.0.0-1033.38, 5.0.0-1030.34
Ubuntu:16.04:LTSlinux-raspi24.4.0-1010.12, 4.4.0-1012.16, 4.4.0-1016.22
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-15.16~18.04.1, 5.0.0-17.18~18.04.1, 5.0.0-19.20~18.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips4.15.0-1001.1, 0
Ubuntu:18.04:LTSlinux-gke-5.35.3.0-1012.13~18.04.1, 5.3.0-1014.15~18.04.1, 5.3.0-1016.17~18.04.1
Ubuntu:18.04:LTSlinux-snapdragon4.4.0-1078.83, 4.15.0-1074.81, 4.4.0-1081.86
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1050.54, 4.4.0-1040.43, 4.4.0-1023.23

…and 43 more

Timeline

References

Open in Interactive Console →