kernel: the copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check
Published Nov 28, 2020
7.0
HIGHCVSS 3.1
EPSS 0.36%
Description
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
Affected products
No data.
Configuration 1
- ≥ 4.5.5 · < 4.9.228
- ≥ 4.10 · < 4.14.185
- ≥ 4.15 · < 4.19.129
- ≥ 4.20 · < 5.4.48
- ≥ 5.5 · < 5.7.5
Configuration 2
- n/a
- n/a
- n/a
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-348.el8
Fixed · RHSA-2021:4356
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-348.rt7.130.el8
Fixed · RHSA-2021:4140
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-0:4.18.0-193.87.1.el8_2
Fixed · RHSA-2022:5220
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-rt-0:4.18.0-193.87.1.rt13.137.el8_2
Fixed · RHSA-2022:5224
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.57.1.el8_4
Fixed · RHSA-2022:5626
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.57.1.rt7.129.el8_4
Fixed · RHSA-2022:5633
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-348.el8 | Fixed | RHSA-2021:4356 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-348.rt7.130.el8 | Fixed | RHSA-2021:4140 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-0:4.18.0-193.87.1.el8_2 | Fixed | RHSA-2022:5220 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-rt-0:4.18.0-193.87.1.rt13.137.el8_2 | Fixed | RHSA-2022:5224 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.57.1.el8_4 | Fixed | RHSA-2022:5626 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.57.1.rt7.129.el8_4 | Fixed | RHSA-2022:5633 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has been rated as having Moderateimpact because, based on Red Hat's assessment, this issue is hard to exploit in practice because the race window is too small for it to be reliable.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00365) | 27.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.36% (0.00360) | 27.67th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00029) | 5.24th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.08% (0.00080) | 34.79th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.08% (0.00080) | 34.61th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00080) | 32.60th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.67% (0.01669) | 53.27th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Jan 5, 2022 | 1.04% (0.01040) | 65.70th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (8)
- https://access.redhat.com/security/cve/CVE-2020-29368 Vendor Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2045 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1903244 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.5 x_refsource_MISCRelease NotesVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c444eb564fb16645c172d550359cb3d75fe8a040 x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-29368
- https://security.netapp.com/advisory/ntap-20210108-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-29368
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-29368 | Vendor Advisory | |
| https://bugs.chromium.org/p/project-zero/issues/detail?id=2045 | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1903244 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.5 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c444eb564fb16645c172d550359cb3d75fe8a040 | x_refsource_MISCPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-29368 | ||
| https://security.netapp.com/advisory/ntap-20210108-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-29368 |
Change history (0)
No recorded changes yet.