#VU19564 Buffer overflow in Linux kernel - CVE-2018-20854
Published: July 31, 2019
Linux kernel
Linux Foundation
Description
The vulnerability allows a local attacker to access sensitive information on a targeted system.
The vulnerability exists due to improper memory operations performed by the "phy-ocelot-serdes.c" file. A local authenticated attacker can make a malicious request, cause an off-by-one out-of-bounds read condition and access sensitive information on the targeted system.