CVE-2020-11884
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2020-11884 affects Linux kernel versions 4.19 through 5.6.7 on the s390 platform. The vulnerability was discovered by Al Viro and disclosed in April 2020. It involves a race condition in the enable_sacf_uaccess function in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade (Ubuntu Security, Debian Security).

Technical details

The vulnerability stems from a race condition in the s390 platform's memory management code where page table upgrades in kernel sections using secondary address mode can interfere with kernel instructions. When a thread is in secondary space mode with control register 1 pointing to kernel page table, a concurrent page table upgrade from another thread can cause the instruction fetching to occur through an incorrect page table mapping (Kernel Git). The vulnerability has a CVSS v3.1 base score of 7.0 (High) with vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (Ubuntu Security).

Impact

A successful exploitation of this vulnerability could allow a local attacker to cause a denial of service (system crash) or execute arbitrary code with elevated privileges on affected s390x systems (Ubuntu Security, Debian Security).

Exploitability

The vulnerability requires local access and can be exploited by a local attacker. The attack complexity is considered high due to the specific timing requirements needed to trigger the race condition (Ubuntu Security).

Mitigation and workarounds

The vulnerability was fixed in Linux kernel version 5.6.8. Multiple Linux distributions have released patches including Ubuntu (versions 20.04, 19.10, 18.04, 16.04), Debian (version 4.19.98-1+deb10u1), and Fedora (versions 30, 31, 32). The fix involves protecting against concurrent page table upgrades by disabling interrupts in enable_sacf_uaccess and only updating control registers currently in use for user processes (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management