A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers. The impact would depend on the underlying system call and can range from denial of service to information leak to memory corruption resulting in code execution within the kernel. See NCC-ZEP-005 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published: 2020-05-11T22:26:17.372048Z

Updated: 2024-09-16T16:37:34.272Z

Reserved: 2020-03-04T00:00:00

Link: CVE-2020-10067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-11T23:15:12.083

Modified: 2024-11-21T04:54:44.413

Link: CVE-2020-10067

cve-icon Redhat

No data.