{"id":"CVE-2020-29374","title":"An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c","summary":"An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operati…","severity":"low","cvss":3.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-362","CWE-863"],"vendor":"netapp","product":"solidfire_&_hci_management_node","affected":["linux_kernel < 5.7.3","debian_linux = 9.0","debian_linux = 10.0","500f_firmware","a250_firmware","h410c_firmware","solidfire_&_hci_management_node","solidfire_&_hci_storage_node","hci_compute_node_bios"],"patched":["linux_kernel 5.7.3"],"published":"2020-11-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:27.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-29374","references":[{"url":"http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html","label":"cve@mitre.org"},{"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=2045","label":"cve@mitre.org"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.3","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=17839856fd588f4ab6b789f482ed3ffd7c403e1f","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20210115-0002/","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2022/dsa-5096","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=2045","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=17839856fd588f4ab6b789f482ed3ffd7c403e1f","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210115-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5096","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00407,"epssPercentile":0.32884,"ingestedAt":"2026-10-08T22:11:53.722Z","slug":"CVE-2020-29374","body":"## Overview\n\nAn issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.\n\n## Affected\n\n- `linux_kernel < 5.7.3`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `500f_firmware`\n- `a250_firmware`\n- `h410c_firmware`\n- `solidfire_&_hci_management_node`\n- `solidfire_&_hci_storage_node`\n- `hci_compute_node_bios`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.7.3`","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":19.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}