Vulnerability Name:

CVE-2020-11884 (CCN-181204)

Assigned:2020-04-28
Published:2020-04-28
Updated:2022-10-29
Summary:In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.
CVSS v3 Severity:7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.0 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.1 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-362
CWE-1251
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-11884

Source: XF
Type: UNKNOWN
linux-kernel-cve202011884-code-exec(181204)

Source: MISC
Type: Mailing List, Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=215d1f3928713d6eaec67244bcda72105b898000

Source: CCN
Type: Linux Kernel GIT Repository
Merge tag 'cve-2020-11884' from emailed bundle

Source: CONFIRM
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3f777e19d171670ab558a6d5e6b1ac7f9b6c574f

Source: FEDORA
Type: Third Party Advisory
FEDORA-2020-b453269c4e

Source: FEDORA
Type: Third Party Advisory
FEDORA-2020-16f9239805

Source: FEDORA
Type: Third Party Advisory
FEDORA-2020-64d46a6e29

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20200608-0001/

Source: UBUNTU
Type: Third Party Advisory
USN-4342-1

Source: UBUNTU
Type: Third Party Advisory
USN-4343-1

Source: UBUNTU
Type: Third Party Advisory
USN-4345-1

Source: DEBIAN
Type: Third Party Advisory
DSA-4667

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-11884

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version >= 4.19 and <= 5.6.7)

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/a:netapp:cloud_backup:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:element_software:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:solidfire:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:hci_management_node:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
  • OR cpe:/h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:netapp:a700s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:a700s:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h300s:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h500s:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h700s:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h300e:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h500e:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h700e:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h410s:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h410c:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h610c:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h610s:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:h410c:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:5.6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:202011884
    V
    CVE-2020-11884
    2023-06-22
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:685
    P
    Security update for bind (Important)
    2022-08-09
    oval:org.opensuse.security:def:665
    P
    Security update for samba (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:3567
    P
    libXtst6-1.2.2-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3453
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:1400
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important) (in QA)
    2022-06-27
    oval:org.opensuse.security:def:95078
    P
    reiserfs-kmp-default-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2960
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95083
    P
    kernel-azure-5.14.21-150400.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94590
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95197
    P
    kernel-default-extra-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95028
    P
    kernel-docs-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:89
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1792
    P
    Security update for MozillaThunderbird (Important)
    2021-12-22
    oval:org.opensuse.security:def:49126
    P
    Security update for runc (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:66952
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:94182
    P
    (Important)
    2021-08-17
    oval:org.opensuse.security:def:2013
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2036
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63102
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100891
    P
    libXv-devel-1.0.11-1.23 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1018
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101277
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72738
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100895
    P
    libXxf86vm-devel-1.1.4-1.23 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63019
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101039
    P
    perl-Convert-ASN1-0.27-1.6.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71848
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1930
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100851
    P
    grub2-2.04-20.4 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62107
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100865
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:94178
    P
    (Important)
    2021-07-14
    oval:org.opensuse.security:def:66860
    P
    Security update for ffmpeg (Important)
    2021-07-14
    oval:org.opensuse.security:def:1465
    P
    Security update for postgresql13 (Moderate)
    2021-07-11
    oval:org.opensuse.security:def:69672
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:73643
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:66817
    P
    Security update for pam_radius (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:93741
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:70207
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:66759
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:70203
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:69777
    P
    Security update for subversion (Important)
    2021-02-10
    oval:org.opensuse.security:def:70308
    P
    Security update for python (Important)
    2021-02-09
    oval:org.opensuse.security:def:66851
    P
    Security update for go1.14 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:66725
    P
    Security update for libzypp, zypper (Moderate)
    2021-01-13
    oval:org.opensuse.security:def:70173
    P
    Security update for openssh (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:66421
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-11
    oval:org.opensuse.security:def:72678
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1999
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107517
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62959
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117075
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2534
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94326
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63114
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107557
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94138
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117115
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71515
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1870
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100454
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61774
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2025
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107561
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63088
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117119
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107120
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63623
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116678
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107705
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117220
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:66329
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:49787
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73525
    P
    perl-Net-Libproxy on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50233
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73112
    P
    kernel-default on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72994
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:70068
    P
    libQt5OpenGLExtensions-devel-static on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49852
    P
    osc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73508
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73390
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49841
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70102
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50179
    P
    bogofilter-common on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73542
    P
    kernel-azure on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49072
    P
    cpp7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73424
    P
    libgypsy-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49906
    P
    kernel-azure on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20202102
    P
    RHSA-2020:2102: kernel security and bug fix update (Important)
    2020-05-12
    BACK
    linux linux kernel *
    canonical ubuntu linux 16.04
    canonical ubuntu linux 18.04
    canonical ubuntu linux 19.10
    canonical ubuntu linux 20.04
    debian debian linux 10.0
    fedoraproject fedora 30
    fedoraproject fedora 31
    fedoraproject fedora 32
    netapp cloud backup -
    netapp element software -
    netapp steelstore cloud integrated storage -
    netapp solidfire -
    netapp hci management node -
    netapp active iq unified manager -
    netapp solidfire baseboard management controller -
    netapp bootstrap os -
    netapp hci compute node -
    netapp a700s firmware -
    netapp a700s -
    netapp h300s firmware -
    netapp h300s -
    netapp h500s firmware -
    netapp h500s -
    netapp h700s firmware -
    netapp h700s -
    netapp h300e firmware -
    netapp h300e -
    netapp h500e firmware -
    netapp h500e -
    netapp h700e firmware -
    netapp h700e -
    netapp h410s firmware -
    netapp h410s -
    netapp h410c firmware -
    netapp h410c -
    netapp h610c firmware -
    netapp h610c -
    netapp h610s firmware -
    netapp h610s -
    netapp h410c firmware -
    netapp h410c -
    linux linux kernel 5.6.0