2.1
CVSSv2

CVE-2020-9391

Published: 25/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in the Linux kernel 5.4 and 5.5 up to and including 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

linux linux kernel 5.4

fedoraproject fedora 31

netapp cloud backup -

netapp steelstore cloud integrated storage -

netapp data availability services -

netapp solidfire -

netapp hci management node -

netapp active iq unified manager -

netapp h410c_firmware -