Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-29374 Details

Description

An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html CVEExploitThird Party AdvisoryVDB Entry
https://bugs.chromium.org/p/project-zero/issues/detail?id=2045 CVEExploitIssue TrackingThird Party Advisory
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.3 CVERelease NotesThird Party AdvisoryVendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=17839856fd588f4ab6b789f482ed3ffd7c403e1f CVEPatchVendor Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html CVEMailing ListThird Party Advisory

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')[email protected]
CWE-863Incorrect Authorization[email protected]

Affected Products

ProductVersions

Change History

16 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-29374
NVD Published Date:
Nov 28, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]