PT-2020-5105 · Linux+7 · Linux Kernel+7

Syzbot

·

Published

2020-09-02

·

Updated

2022-11-21

·

CVE-2020-25641

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.9-rc7
Description The issue is related to a flaw in the Linux kernel's implementation of biovecs, which can cause the kernel to enter an infinite loop when a zero-length biovec request is issued by the block subsystem. This can result in a denial of service. A local attacker with basic privileges can exploit this issue by issuing requests to a block device.
Recommendations For Linux kernel versions prior to 5.9-rc7, update to version 5.9-rc7 or later to resolve the issue. As a temporary workaround, consider restricting access to block devices to minimize the risk of exploitation.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4431
ALT-PU-2020-2982
ALT-PU-2020-3069
ALT-PU-2020-3074
ALT-PU-2020-3210
ALT-PU-2020-3553
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2020-05701
CESA-2020_4431
CESA-2020_4609
CVE-2020-25641
DLA-2385-1
DLA-2420-1
DLA-2420-2
MGASA-2020-0392
OPENSUSE-SU-2020:1655-1
OPENSUSE-SU-2020:1698-1
OPENSUSE-SU-2020:2112-1
OPENSUSE-SU-2020_1655-1
OPENSUSE-SU-2020_1698-1
OPENSUSE-SU-2020_2112-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
RHSA-2020:4431
RHSA-2020:4609
RHSA-2020:5079
RHSA-2020:5374
RHSA-2020_4431
RHSA-2020_4609
RHSA-2021:0073
RHSA-2021:0136
SUSE-SU-2020:2904-1
SUSE-SU-2020:2905-1
SUSE-SU-2020:2906-1
SUSE-SU-2020:2907-1
SUSE-SU-2020:2980-1
SUSE-SU-2020:2999-1
SUSE-SU-2020:3014-1
SUSE-SU-2020:3230-1
SUSE-SU-2020:3491-1
SUSE-SU-2020:3503-1
SUSE-SU-2020:3532-1
SUSE-SU-2020:3544-1
USN-4576-1
USN-4660-1
USN-4660-2
USN-4752-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu