PT-2020-2428 · Linux+4 · Linux Kernel+4
Published
2020-02-21
·
Updated
2024-08-04
·
CVE-2020-12768
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.6
Description
The issue is related to a memory leak in the
svm cpu uninit function in arch/x86/kvm/svm.c. This leak occurs once at boot time and is negligible in size. It cannot be triggered at will. Third parties dispute this issue due to its one-time nature and minimal impact.Recommendations
For Linux kernel versions prior to 5.6, update to version 5.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
svm cpu uninit function until a patch is available. However, given the nature of the leak, the impact is considered minimal, and the dispute over its significance is noted.Fix
Memory Leak
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu