CVE-2020-28097
⚪ Do wiadomości
Błąd odczytu poza granicami w subsystemie vgacon w jądrze Linux może prowadzić do ujawnienia pamięci.
CVSS
5.9
EPSS
0.5%
Exploit
poc
Vendor
netapp
Opis źródłowy (NVD)
The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2021-06-24 12:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:27 UTC |
Referencje
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.10 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=973c096f6a85e5b5f2a295126ba6928d9a6afd45 ([email protected]) [Patch, Vendor Advisory]
- https://github.com/torvalds/linux/commit/973c096f6a85e5b5f2a295126ba6928d9a6afd45 ([email protected]) [Patch, Third Party Advisory]
- https://seclists.org/oss-sec/2020/q3/176 ([email protected]) [Exploit, Mailing List, Patch, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20210805-0001/ ([email protected]) [Third Party Advisory]