PT-2021-2371 · Linux+5 · Linux Kernel+5

Published

2021-01-14

·

Updated

2024-06-15

·

CVE-2020-25639

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.12-rc1
Description The issue is related to a NULL pointer dereference flaw in the Linux kernel's GPU Nouveau driver. This flaw can be exploited by a local user to crash the system by calling the ioctl function with the DRM IOCTL NOUVEAU CHANNEL ALLOC parameter.
Recommendations For Linux kernel versions prior to 5.12-rc1, update to version 5.12-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ioctl function with the DRM IOCTL NOUVEAU CHANNEL ALLOC parameter to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1447
ALT-PU-2021-1525
ALT-PU-2021-1869
ALT-PU-2021-1888
ALT-PU-2021-1896
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
AZL-6523
BDU:2021-01611
CVE-2020-25639
MGASA-2021-0117
MGASA-2021-0152
OPENSUSE-SU-2021:0060-1
OPENSUSE-SU-2021:0075-1
OPENSUSE-SU-2021_0060-1
OPENSUSE-SU-2021_0075-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2021:0347-1
SUSE-SU-2021:0348-1
SUSE-SU-2021:0353-1
SUSE-SU-2021:0354-1
SUSE-SU-2021:0427-1
SUSE-SU-2021:0433-1
SUSE-SU-2021:0434-1
SUSE-SU-2021:0438-1
SUSE-SU-2021:0532-1
SUSE-SU-2021_0348-1
SUSE-SU-2021_0532-1
USN-4911-1
USN-4945-1
USN-4945-2
USN-4949-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu