CVE-2020-10028: Multiple Syscalls In GPIO Subsystem Performs No Argument Validation
Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10028?
CVE-2020-10028 has been classified with a severity level that raises concerns due to insufficient argument validation in multiple syscalls.
How do I fix CVE-2020-10028?
To mitigate CVE-2020-10028, upgrade to a version of Zephyr that addresses the argument validation issues.
Which versions of Zephyr are affected by CVE-2020-10028?
CVE-2020-10028 affects Zephyr versions 1.14.0 and later, as well as versions 2.1.0 and later.
Can CVE-2020-10028 lead to security exploits?
Yes, due to insufficient argument validation, CVE-2020-10028 can potentially allow attackers to exploit the system.
What are the implications of ignoring CVE-2020-10028?
Ignoring CVE-2020-10028 may leave your system vulnerable to security breaches that exploit the syscall vulnerabilities.