CVE-2020-10023: Shell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trim
The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel. See NCC-NCC-019 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10023?
The severity of CVE-2020-10023 is classified as high due to the potential for denial of service and possible code execution.
How do I fix CVE-2020-10023?
To fix CVE-2020-10023, update to a patched version of Zephyr that resolves the buffer overflow vulnerability.
What systems are affected by CVE-2020-10023?
CVE-2020-10023 affects Zephyr versions 1.14.1 and 2.1.0.
What type of vulnerability is CVE-2020-10023?
CVE-2020-10023 is a buffer overflow vulnerability in the shell subsystem of the Zephyr kernel.
What could happen if CVE-2020-10023 is exploited?
If CVE-2020-10023 is exploited, it can lead to memory corruption, resulting in system instability or unauthorized code execution.