Buffer access with incorrect length value in Linux kernel - CVE-2020-10774
Published: May 27, 2021 / Updated: June 8, 2021
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
A memory disclosure flaw was found in the Linux kernel's versions before 4.18.0-193.el8 in the sysctl subsystem when reading the /proc/sys/kernel/rh_features file. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.