vulnerability

Amazon Linux AMI: CVE-2020-25285: Security patch for kernel (ALAS-2020-1437)

Severity
6
CVSS
(AV:L/AC:M/Au:M/C:C/I:C/A:C)
Published
Sep 13, 2020
Added
Oct 28, 2020
Modified
May 21, 2025

Description

A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.

Solution

amazon-linux-upgrade-kernel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.