PT-2020-7008 · Linux+5 · Linux Kernel+5

Shisong Qin

·

Published

2020-11-24

·

Updated

2021-09-07

·

CVE-2020-27830

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A vulnerability was found in the Linux Kernel related to the spk ttyio receive buf2() function. The issue is associated with pointer dereference errors, specifically dereferencing spk ttyio synth without checking if it is NULL, which may lead to a NULL-ptr deref crash. Exploitation of this vulnerability could allow an attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3536
ALT-PU-2020-3553
ALT-PU-2020-3556
ALT-PU-2020-3570
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2025-00838
CVE-2020-27830
DLA-2557-1
DSA-4843-1
MGASA-2021-0030
MGASA-2021-0031
OESA-2021-1003
OPENSUSE-SU-2021:0060-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0060-1
OPENSUSE-SU-2021_0242-1
SUSE-SU-2021:0096-1
SUSE-SU-2021:0108-1
SUSE-SU-2021:0117-1
USN-4749-1
USN-4750-1
USN-4751-1
USN-4912-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Linuxmint
Suse
Ubuntu