#VU52687 Incorrect Conversion between Numeric Types in Linux kernel - CVE-2020-28588
Published: April 28, 2021
Linux kernel
Linux Foundation
Description
The vulnerability allows a local attacker to gain unauthorized access to sensitive information on the system.
The vulnerability exists due to incorrect conversion between numeric types in the /proc/pid/syscall functionality. A local attacker can read /proc/pid/syscall to trigger this vulnerability, leading to the kernel leaking memory contents.