CVE-2020-11565

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-11565
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11565.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-11565
Downstream
Related
Published
2020-04-06T01:15:12Z
Modified
2025-08-09T19:01:29Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in the Linux kernel through 5.6.2. mpolparsestr in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community disagrees that this is a vulnerability because the issue “is a bug in parsing mount options which can only be specified by a privileged user, so triggering the bug does not grant any powers not already held.”

Database specific
{
    "isDisputed": true
}
References

Affected packages