7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8 High
AI Score
Confidence
High
0.0004 Low
EPSS
Percentile
14.3%
Issue Overview:
2024-05-23: CVE-2020-14356 was added to this advisory.
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. (CVE-2020-14356)
A flaw was found in the Linux kernel. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2020-14386)
Affected Packages:
kernel
Issue Correction:
Run yum update kernel to update your system.
New Packages:
i686:
kernel-tools-devel-4.14.193-113.317.amzn1.i686
kernel-4.14.193-113.317.amzn1.i686
kernel-debuginfo-4.14.193-113.317.amzn1.i686
perf-debuginfo-4.14.193-113.317.amzn1.i686
perf-4.14.193-113.317.amzn1.i686
kernel-tools-4.14.193-113.317.amzn1.i686
kernel-tools-debuginfo-4.14.193-113.317.amzn1.i686
kernel-debuginfo-common-i686-4.14.193-113.317.amzn1.i686
kernel-devel-4.14.193-113.317.amzn1.i686
kernel-headers-4.14.193-113.317.amzn1.i686
src:
kernel-4.14.193-113.317.amzn1.src
x86_64:
kernel-tools-4.14.193-113.317.amzn1.x86_64
kernel-debuginfo-4.14.193-113.317.amzn1.x86_64
kernel-debuginfo-common-x86_64-4.14.193-113.317.amzn1.x86_64
kernel-4.14.193-113.317.amzn1.x86_64
kernel-headers-4.14.193-113.317.amzn1.x86_64
perf-4.14.193-113.317.amzn1.x86_64
kernel-tools-devel-4.14.193-113.317.amzn1.x86_64
perf-debuginfo-4.14.193-113.317.amzn1.x86_64
kernel-tools-debuginfo-4.14.193-113.317.amzn1.x86_64
kernel-devel-4.14.193-113.317.amzn1.x86_64
Red Hat: CVE-2020-14356, CVE-2020-14386
Mitre: CVE-2020-14356, CVE-2020-14386
7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8 High
AI Score
Confidence
High
0.0004 Low
EPSS
Percentile
14.3%