#VU46814 Input validation error in Linux kernel


Published: 2020-09-10 | Updated: 2020-09-18

Vulnerability identifier: #VU46814

Vulnerability risk: Low

CVSSv3.1: 3.9 [CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:W/RC:C]

CVE-ID: CVE-2020-10773

CWE-ID: CWE-20

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local privileged user to gain access to sensitive information.

A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. A local privileges user can gain access to sensitive data in the memory.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: 5.4.0 rc6


External links
http://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10773
http://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b8e51a6a9db94bc1fb18ae831b3dab106b5a4b5f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability