SB2020022533 - Fedora 31 update for kernel, kernel-headers, kernel-tools



SB2020022533 - Fedora 31 update for kernel, kernel-headers, kernel-tools

Published: February 25, 2020 Updated: April 25, 2025

Security Bulletin ID SB2020022533
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer overflow (CVE-ID: CVE-2020-9391)

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.


Remediation

Install update from vendor's website.