Serenityos · Serenityos · CVE-2019-20172
**Name of the Vulnerable Software and Affected Versions**
SerenityOS versions prior to 2019-12-30
**Description**
The issue allows local users to gain privileges by overwriting a return address found on the kernel stack, due to the failure of Kernel/VM/MemoryManager.cpp to reject syscalls with pointers into the kernel-only virtual address space.
**Recommendations**
For versions prior to 2019-12-30, update to a version released after 2019-12-30 to resolve the issue.