PT-2020-11894 · Zephyr · Zephyr

Ceolin

+1

·

Published

2020-05-11

·

Updated

2020-06-05

·

CVE-2020-10067

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zephyr versions 1.14.1 through 2.1.0 and later versions.
Description A malicious userspace application can cause an integer overflow, bypassing security checks performed by system call handlers. The impact can range from denial of service to information leak to memory corruption, potentially resulting in code execution within the kernel.
Recommendations For zephyr versions 1.14.1 through 2.1.0 and later versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10067

Affected Products

Zephyr