PT-2020-7007 · Linux+5 · Linux Kernel+5

Bodong Zhao

+1

·

Published

2020-11-10

·

Updated

2022-10-19

·

CVE-2020-28941

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.9.9
Description An issue in the Linux kernel's speakup driver allows local attackers to cause a denial of service attack. This occurs due to an invalid free when the line discipline is used more than once. The issue is related to the spk ttyio.c component.
Recommendations For Linux kernel versions through 5.9.9, consider disabling the speakup driver to prevent exploitation until a patch is available. Restrict access to the spk ttyio.c component to minimize the risk of a local denial of service attack.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3439
ALT-PU-2020-3536
ALT-PU-2020-3553
ALT-PU-2020-3570
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2025-00837
CVE-2020-28941
DLA-2483-1
MGASA-2021-0030
MGASA-2021-0031
OPENSUSE-SU-2020:2161-1
OPENSUSE-SU-2020:2260-1
OPENSUSE-SU-2020_2161-1
OPENSUSE-SU-2020_2260-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
SUSE-SU-2020:3713-1
SUSE-SU-2020:3748-1
SUSE-SU-2020:3764-1
USN-4749-1
USN-4750-1
USN-4751-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu