An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-toolsUpgrade python-perfUpgrade perfUpgrade kernel-develUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-develUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade kernelUpgrade kernel-debuginfoUpgrade kernel-tools-debuginfoUpgrade perf-debuginfoUpgrade python-perf-debuginfo | May 28, 2024 | Feb 25, 2020 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Feb 25, 2020 |
| Oracle_linux | — | Upgrade kernel-uek | Oct 5, 2022 | Feb 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub