#VU47051 Out-of-bounds write


Published: 2020-09-25 | Updated: 2022-01-13

Vulnerability identifier: #VU47051

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-14386

CWE-ID: CWE-787

Exploitation vector: Local

Exploit availability: Yes

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local privileged user to execute arbitrary code.

A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: 5.0 - 5.8.0


CPE

External links
http://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14386
http://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=acf69c946233259ab4d64f8869d4037a198c7f06
http://seclists.org/oss-sec/2020/q3/146


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability