A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2483-1 | linux-4.19 security update |
Debian DLA |
DLA-2494-1 | linux security update |
EUVD |
EUVD-2020-21358 | A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height. |
Ubuntu USN |
USN-4679-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4680-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4681-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4683-1 | Linux kernel (OEM) vulnerability |
Ubuntu USN |
USN-4751-1 | Linux kernel vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:48:01.280Z
Reserved: 2020-11-20T00:00:00
Link: CVE-2020-28974
No data.
Status : Modified
Published: 2020-11-20T18:15:12.120
Modified: 2024-11-21T05:23:25.433
Link: CVE-2020-28974
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN