CVEs Blog | G5 Cyber Security

CVE-2020-25212 – A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25212

Reference (s):

Exit mobile version