7.8

CVE-2020-14356

Exploit
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.231
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.189
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.134
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.53
Linux ≫ Linux Kernel Version >= 5.5 < 5.7.10
Redhat ≫ Enterprise Linux Version 8.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Cloud Backup Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.97% 0.57
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4526-1/
Third Party Advisory
https://usn.ubuntu.com/4483-1/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html
Third Party Advisory
Mailing List
https://bugzilla.kernel.org/show_bug.cgi?id=208003
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1868453
Patch
Third Party Advisory
Issue Tracking
https://lore.kernel.org/netdev/CAM_iQpUKQJrj8wE+Qa8NGR3P0L+5Uz=qo-O5+k_P60HzTde6aw%40mail.gmail.com/t/
Vendor Advisory
Exploit
https://security.netapp.com/advisory/ntap-20200904-0002/
Third Party Advisory
https://usn.ubuntu.com/4484-1/
Third Party Advisory