Bug 1168831 - (CVE-2020-11565) VUL-1: CVE-2020-11565: kernel-source: out-of-bounds write due to improper handling of an empty nodelist during mount option parsing
(CVE-2020-11565)
VUL-1: CVE-2020-11565: kernel-source: out-of-bounds write due to improper han...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Kernel Bugs
Security Team bot
https://smash.suse.de/issue/256525/
CVSSv3.1:SUSE:CVE-2020-11565:4.8:(AV...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-04-07 08:46 UTC by Alexandros Toptsoglou
Modified: 2020-06-10 16:03 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2020-04-07 08:46:33 UTC
CVE-2020-11565

An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in
mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist
is mishandled during mount option parsing, aka CID-aa9f7d5172fa.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11565
https://github.com/torvalds/linux/commit/aa9f7d5172fac9bf1f09e678c35e287a40a7b7dd
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11565
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=aa9f7d5172fac9bf1f09e678c35e287a40a7b7dd
Comment 1 Michal Hocko 2020-04-07 09:04:55 UTC
While the issue is real, this requires root to mount the tmpfs. So what is the security aspect of this bug?
Comment 2 Alexandros Toptsoglou 2020-04-07 11:39:53 UTC
Tracked as affected as back as 2.6.32
Comment 3 Borislav Petkov 2020-05-16 08:03:02 UTC
This here says that this has been disputed in the meantime:

https://security-tracker.debian.org/tracker/CVE-2020-11565
Comment 4 Alexandros Toptsoglou 2020-05-27 07:23:24 UTC
Disputed