Lucene search

K
cvelistRedhatCVELIST:CVE-2020-14386
HistorySep 16, 2020 - 12:48 p.m.

CVE-2020-14386

2020-09-1612:48:12
CWE-787
CWE-250
redhat
www.cve.org
7
linux
kernel
memory corruption
root privileges
data confidentiality
data integrity

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

14.2%

A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

CNA Affected

[
  {
    "product": "kernel",
    "vendor": "Linux Kernel",
    "versions": [
      {
        "status": "affected",
        "version": "before 5.9-rc4"
      }
    ]
  }
]

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

14.2%