[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-8835Date: (C)2020-04-08   (M)2024-05-24


In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score : 7.2
Exploit Score: 1.8Exploit Score: 3.9
Impact Score: 5.9Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
FEDORA-2020-4ef0bcc89c
FEDORA-2020-666f3b1ac3
FEDORA-2020-73c00eda1c
N/A
USN-4313-1
http://www.openwall.com/lists/oss-security/2021/07/20/1
https://lore.kernel.org/bpf/20200330160324.15259-1-daniel%40iogearbox.net/T/
https://security.netapp.com/advisory/ntap-20200430-0004/

CPE    2
cpe:/o:linux:linux_kernel
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
CWE    1
CWE-125
OVAL    4
oval:org.secpod.oval:def:70187
oval:org.secpod.oval:def:705417
oval:org.secpod.oval:def:1502892
oval:org.secpod.oval:def:1502891
...

© SecPod Technologies