PT-2020-4972 · Linux+4 · Linux Kernel+4

Jann Horn

·

Published

2020-08-21

·

Updated

2021-05-28

·

CVE-2020-29371

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.8.4
Description An issue was discovered in the romfs dev read function in fs/romfs/storage.c that is related to insufficient input validation, allowing an attacker to gain unauthorized access to protected information. This issue results in uninitialized memory leaks to userspace.
Recommendations For Linux kernel versions prior to 5.8.4, update to version 5.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the romfs dev read function in fs/romfs/storage.c until a patch is available.

Exploit

Fix

Use of Uninitialized Resource

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2688
ALT-PU-2020-2770
ALT-PU-2020-3210
ALT-PU-2020-3553
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2020-05549
CVE-2020-29371
OPENSUSE-SU-2020:2161-1
OPENSUSE-SU-2020:2193-1
OPENSUSE-SU-2020:2260-1
OPENSUSE-SU-2020_2161-1
OPENSUSE-SU-2020_2193-1
OPENSUSE-SU-2020_2260-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
SUSE-SU-2020:3713-1
SUSE-SU-2020:3717-1
SUSE-SU-2020:3718-1
SUSE-SU-2020:3748-1
SUSE-SU-2020:3764-1
SUSE-SU-2020:3766-1
SUSE-SU-2020:3798-1
SUSE-SU-2021:0097-1
SUSE-SU-2021:0098-1
SUSE-SU-2021:0434-1
SUSE-SU-2021:0438-1
USN-4752-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu