← Back

CVE-2020-9391

nvd nist
Published: Feb 25, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.

Affected (10)

1 product
Linux Kernel
1 product
Fedora
7 products
Active Iq Unified Manager
Cloud Backup
Data Availability Services
Hci Management Node
Solidfire
H410c Firmware
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 5.5 to 5.5.6
Version 5.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 31
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410c
All versions

References (10)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.