Lucene search

K
cve[email protected]CVE-2020-28974
HistoryNov 20, 2020 - 6:15 p.m.

CVE-2020-28974

2020-11-2018:15:12
CWE-125
web.nvd.nist.gov
253
cve-2020-28974
slab-out-of-bounds read
fbcon
linux kernel
local attackers
privileged information
kernel crash

6.1 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:P/I:P/A:C

5 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.

Affected configurations

NVD
Node
linuxlinux_kernelRange<5.9.7
Node
debiandebian_linuxMatch9.0

6.1 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:P/I:P/A:C

5 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H

5.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%