Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-14386
HistorySep 04, 2020 - 12:00 a.m.

CVE-2020-14386

2020-09-0400:00:00
ubuntu.com
ubuntu.com
22
linux kernel
memory corruption
root privileges
data confidentiality
data integrity

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

14.2%

A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can
be exploited to gain root privileges from unprivileged processes. The
highest threat from this vulnerability is to data confidentiality and
integrity.

Notes

Author Note
sbeattie requires CAP_NET_RAW
cascardo Added break as investigated by Solar Designer.
sbeattie older backports without 8e8e2951e309 will need second lore.kernel.org variant
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-117.118UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-47.51UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1082.86UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1024.24UNKNOWN
ubuntu18.04noarchlinux-aws-5.3< 5.3.0-1035.37UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1024.24~18.04.1UNKNOWN
ubuntu16.04noarchlinux-aws-hwe< 4.15.0-1082.86~16.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1025.25UNKNOWN
ubuntu14.04noarchlinux-azure< 4.15.0-1095.105~14.04.1UNKNOWN
ubuntu16.04noarchlinux-azure< 4.15.0-1095.105~16.04.1UNKNOWN
Rows per page:
1-10 of 371

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

14.2%