kernel: use-after-free in show_numa_stats function
Published Nov 28, 2020
5.3
MEDIUMCVSS 3.1
EPSS 0.32%
Description
An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.
Affected products
No data.
- ≥ 4.19 · < 4.19.64
- ≥ 5.2 · ≤ 5.2.17
- 5.3
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.36.2.el7
Fixed · RHSA-2021:2725
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.36.2.rt56.1179.el7
Fixed · RHSA-2021:2726
Red Hat Enterprise Linux 7.7 Advanced Update Support
kernel-0:3.10.0-1062.59.1.el7
Fixed · RHSA-2021:3987
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
kernel-0:3.10.0-1062.59.1.el7
Fixed · RHSA-2021:3987
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kernel-0:3.10.0-1062.59.1.el7
Fixed · RHSA-2021:3987
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.36.2.el7 | Fixed | RHSA-2021:2725 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.36.2.rt56.1179.el7 | Fixed | RHSA-2021:2726 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | kernel-0:3.10.0-1062.59.1.el7 | Fixed | RHSA-2021:3987 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | kernel-0:3.10.0-1062.59.1.el7 | Fixed | RHSA-2021:3987 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kernel-0:3.10.0-1062.59.1.el7 | Fixed | RHSA-2021:3987 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
As the NUMA features are built-in and enabled by default, the NUMA functionality can be disabled at boot time by providing the kernel parameter, numa=off. The method of providing this parameter depends on the operating system version, see KCS article https://access.redhat.com/solutions/23216. Disabling this feature may have significant performance impacts and the administrator should consider if the performance penalty is a problem. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.
References (7)
- https://access.redhat.com/security/cve/CVE-2019-20934 Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1913 x_refsource_MISCIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1902788 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.6 x_refsource_MISCVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=16d51a590a8ce3befb1308e0e7ab77f3b661af33 x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20934
- https://www.cve.org/CVERecord?id=CVE-2019-20934
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20934 | Vendor Advisory | |
| https://bugs.chromium.org/p/project-zero/issues/detail?id=1913 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1902788 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.6 | x_refsource_MISCVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=16d51a590a8ce3befb1308e0e7ab77f3b661af33 | x_refsource_MISCPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20934 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-20934 |
Change history (0)
No recorded changes yet.