kernel: race condition in __mptctl_ioctl function in drivers/message/fusion/mptctl.c allows local users to hold an incorrect lock during the ioctl operation
Published May 5, 2020
4.1
MEDIUMCVSS 3.1
EPSS 0.33%
Description
The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, i.e., a "double fetch" vulnerability, aka CID-28d76df18f0a. NOTE: the vendor states "The security impact of this bug is not as bad as it could have been because these operations are all privileged and root already has enormous destructive power."
Affected products
No data.
- < 5.4.14
No data.
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is to skip loading the affected module Fusion MPT base driver 'mptctl' onto the system until we have a fix available. This can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2020-12652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1831849 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.14 x_refsource_MISCRelease NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=28d76df18f0ad5bcf5fa48510b225f0ed262a99b x_refsource_MISCPatchVendor Advisory
- https://github.com/torvalds/linux/commit/28d76df18f0ad5bcf5fa48510b225f0ed262a99b x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2020-12652
- https://security.netapp.com/advisory/ntap-20200608-0001/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2020-12652
- https://www.debian.org/security/2020/dsa-4698 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.