CVE-2020-29369
Linux Kernel vulnerability analysis and mitigation

Overview

A race condition vulnerability (CVE-2020-29369) was discovered in mm/mmap.c in the Linux kernel before version 5.7.11. The vulnerability involves a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, identified as CID-246c320a8cfe (CVE MITRE, NVD).

Technical details

The vulnerability occurs when a VMA (Virtual Memory Area) with VM_GROWSDOWN or VM_GROWSUP flag set can change its size under mmap_read_lock(). This leads to a race condition with __do_munmap() where one thread can modify the VMA while another thread is attempting to unmap the region. The issue specifically involves the expand_downwards and expand_upwards functions conflicting with page-table free operations. The vulnerability has a CVSS v3.1 Base Score of 7.0 (HIGH) with vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The vulnerability could allow a local attacker with user privileges to crash the system or potentially expose sensitive information (NetApp Advisory).

Exploitability

The vulnerability requires local access with low privileges. It has high attack complexity, requires no user interaction, and has a limited scope. The vulnerability was discovered by Jann Horn and has been publicly disclosed (Kernel Commit).

Mitigation and workarounds

The vulnerability was fixed in Linux kernel version 5.7.11. The fix involves avoiding downgrading mmap_lock in __do_munmap() if detached VMAs are next to VM_GROWSDOWN or VM_GROWSUP VMA. Users should upgrade to Linux kernel version 5.7.11 or later to address this vulnerability (Kernel Changelog).

Community reactions

The vulnerability was initially assigned CVE-2021-20200 by Red Hat but was later identified as a duplicate of CVE-2020-29369. This led to some confusion in the security community, as evidenced by discussions on the oss-security mailing list (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68427MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra
NoYesAug 10, 2026
CVE-2026-68426MEDIUM4.7
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-igx
NoYesAug 10, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 12, 2026
CVE-2026-68430NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-partner
NoYesAug 12, 2026
CVE-2026-68428NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-ibm-6.8
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management