Lucene search

K
redhatcveRedhat.comRH:CVE-2020-11494
HistoryApr 20, 2020 - 6:07 p.m.

CVE-2020-11494

2020-04-2018:07:10
redhat.com
access.redhat.com
23

0.0005 Low

EPSS

Percentile

18.2%

A flaw was discovered in slc_bump in drivers/net/can/slcan.c in CAN Communication Protocol. It allows a local attacker with special user privilege (or root) to read sensitive kernel stack information (considering CONFIG_INIT_STACK_ALL is not enabled) when a partially initialized data structure is exposed over the network layer.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.