An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-develUpgrade kernel-tools-develUpgrade perfUpgrade kernel-toolsUpgrade kernel-debuginfo-common-aarch64Upgrade python-perfUpgrade kernel-tools-debuginfoUpgrade perf-debuginfoUpgrade kernel-debuginfoUpgrade kernelUpgrade kernel-headersUpgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfo | May 28, 2024 | Feb 25, 2020 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Feb 25, 2020 |
| Oracle_linux | — | Upgrade kernel-uek | Oct 5, 2022 | Feb 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub