CVE-2020-28588

CVSS v3.1 5.5 (Medium)
55% Progress
CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.05 % (21th)
0.05% Progress
Affected Products 1
Advisories 5

An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.

Weaknesses
CWE-681
Incorrect Conversion between Numeric Types
CVE Status
PUBLISHED
CNA
Talos
Published Date
2021-05-10 19:15:08
(3 years ago)
Updated Date
2022-06-07 18:39:03
(2 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 5.4.66 cpe:2.3:o:linux:linux_kernel:5.4.66
  Linux Kernel 5.9.8 cpe:2.3:o:linux:linux_kernel:5.9.8
  Linux Kernel 5.10 Rc4 cpe:2.3:o:linux:linux_kernel:5.10:rc4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...