Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Grsecurity

#40540of 53,611
6.6Total CVSS
Vulnerabilities · 1
PT-2020-5048
6.6
2020-09-05
Linux · Linux Kernel · CVE-2020-25285
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 5.8.8 **Description** The issue is related to a race condition between hugetlb sysctl handlers in the Linux kernel, which can be exploited by local attackers to corrupt memory, cause a NULL pointer dereference, or have unspecified other impact. This is due to errors in synchronization when using a shared resource. **Recommendations** For Linux kernel versions prior to 5.8.8, update to version 5.8.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the hugetlb sysctl handlers to minimize the risk of exploitation.