4.1
CVE-2020-25656
- EPSS 0.43%
- Veröffentlicht 02.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:22
- Erkennungen
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.10
Linux ≫ Linux Kernel Version 5.10 Update rc1
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build12533 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build12658 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build12859 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build13170 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build13586 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build13861 SwPlatform vsphere
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.345 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.1 | 0.5 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:P/I:N/A:N
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html
https://lists.debian.org/debian-lts-announce/2020/12/msg00027.html
https://bugzilla.redhat.com/show_bug.cgi?id=1888726
https://lkml.org/lkml/2020/10/16/84
https://lkml.org/lkml/2020/10/29/528
https://www.starwindsoftware.com/security/sw-20210325-0006/