Skip to content

kernel CVE-2020-25704

Moderate
etungsten published GHSA-jrx3-x2ph-rj9p Jan 15, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.0.5

Patched versions

1.0.5

Description

A memory leak in the Linux kernel performance monitoring subsystem was found in the use of PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve resources causing denial of service.

Severity

Moderate

CVE ID

CVE-2020-25704

Weaknesses

No CWEs