PT-2020-6092 · Linux+4 · Linux Kernel+4
Published
2020-09-24
·
Updated
2022-06-07
·
CVE-2020-28588
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions 5.1 through 5.10-rc4
Description
An information disclosure issue exists in the
/proc/pid/syscall functionality of the Linux Kernel. This issue is related to a deficiency in the data type conversion mechanism, allowing an attacker to read /proc/pid/syscall and trigger the vulnerability, leading to the kernel leaking memory contents.Recommendations
For Linux Kernel versions 5.1 through 5.10-rc4, consider restricting access to the
/proc/pid/syscall functionality until a patch is available.
As a temporary workaround, avoid using the /proc/pid/syscall endpoint to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Information Disclosure
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linux Kernel
Linuxmint
Ubuntu