Medium severity5.5NVD Advisory· Published Feb 25, 2020· Updated Jun 17, 2026
CVE-2020-9391
CVE-2020-9391
Description
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
- Linux/Linux kerneldescription
Patches
Vulnerability mechanics
References
5- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/nvdMailing ListPatchVendor Advisory
- www.openwall.com/lists/oss-security/2020/02/25/6nvdExploitMailing ListThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingPatchThird Party Advisory
- security.netapp.com/advisory/ntap-20200313-0003/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O4LH35HOPBJIKYHYFXMBBM75DN75PZHZ/nvd
News mentions
0No linked articles in our index yet.