PT-2020-6161 · Linux+3 · Linux Kernel+3

Nopnop Nop

·

Published

2020-09-14

·

Updated

2022-04-06

·

CVE-2020-28097

CVSS v3.1

5.9

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.8.10
Description The vgacon subsystem in the Linux kernel mishandles software scrollback, leading to a vgacon scrolldelta out-of-bounds read. This issue may allow an attacker to impact the availability of protected information.
Recommendations For Linux kernel versions prior to 5.8.10, update to version 5.8.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the vgacon subsystem until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2864
ALT-PU-2020-2888
ALT-PU-2020-3210
ALT-PU-2020-3553
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2021-03291
CVE-2020-28097
OESA-2021-1279
OPENSUSE-SU-2022:0363-1
OPENSUSE-SU-2022:0370-1
OPENSUSE-SU-2022_0363-1
OPENSUSE-SU-2022_0370-1
SUSE-SU-2022:0363-1
SUSE-SU-2022:0364-1
SUSE-SU-2022:0370-1
SUSE-SU-2022:0372-1
SUSE-SU-2022:0543-1
SUSE-SU-2022:0555-1
SUSE-SU-2022_0363-1
SUSE-SU-2022_0364-1
SUSE-SU-2022_0370-1
SUSE-SU-2022_0372-1
SUSE-SU-2022_0543-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Suse