CVE-2020-28588
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/05/2021
Last modified:
07/06/2022
Description
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:5.4.66:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:5.9.8:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:5.10:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page