PT-2020-5968 · Linux+4 · Linux Kernel+4
Luca Bruno
·
Published
2020-06-18
·
Updated
2022-11-07
·
CVE-2020-10781
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions prior to 5.8-rc6
Description
The issue is related to the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot add file can create ZRAM device nodes in the /dev/ directory. This action allocates kernel memory without accounting for the user, potentially leading to a large consumption of system memory. Continual reading of the device may trigger the Out-of-Memory (OOM) killer, causing it to activate and terminate random userspace processes, which could make the system inoperable.
Recommendations
For Linux Kernel versions prior to 5.8-rc6, consider restricting access to the /sys/class/zram-control/hot add file to prevent unauthorized creation of ZRAM device nodes. As a temporary workaround, limit the ability of local users to read this file until a patch is available. Additionally, monitor system memory usage closely to detect potential exploitation attempts.
Fix
Incorrect Permission
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Linuxmint
Suse
Ubuntu