PT-2020-6092 · Linux+4 · Linux Kernel+4

Published

2020-09-24

·

Updated

2022-06-07

·

CVE-2020-28588

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux Kernel versions 5.1 through 5.10-rc4
Description An information disclosure issue exists in the /proc/pid/syscall functionality of the Linux Kernel. This issue is related to a deficiency in the data type conversion mechanism, allowing an attacker to read /proc/pid/syscall and trigger the vulnerability, leading to the kernel leaking memory contents.
Recommendations For Linux Kernel versions 5.1 through 5.10-rc4, consider restricting access to the /proc/pid/syscall functionality until a patch is available. As a temporary workaround, avoid using the /proc/pid/syscall endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2873
ALT-PU-2020-3439
ALT-PU-2020-3499
ALT-PU-2020-3500
ALT-PU-2020-3507
ALT-PU-2020-3509
ALT-PU-2020-3535
ALT-PU-2020-3536
ALT-PU-2021-1083
ALT-PU-2021-1211
ALT-PU-2021-1745
BDU:2021-02982
CVE-2020-28588
MGASA-2021-0030
MGASA-2021-0031
USN-4750-1
USN-4751-1
USN-4752-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Linuxmint
Ubuntu