An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
2020-11-28T07:15:11.960
2024-11-21T05:23:56.503
Modified
CVSSv3.1: 3.6 (LOW)
AV:L/AC:M/Au:N/C:P/I:P/A:N
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 5.7.3 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | netapp | 500f_firmware | - | Yes |
Hardware | netapp | 500f | - | No |
Operating System | netapp | a250_firmware | - | Yes |
Hardware | netapp | a250 | - | No |
Operating System | netapp | h410c_firmware | - | Yes |
Hardware | netapp | h410c | - | No |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Application | netapp | solidfire_\&_hci_storage_node | - | Yes |
Operating System | netapp | hci_compute_node_bios | - | Yes |