CVE-2020-28915: Medium severity linux kernel vulnerability
A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.
Other sources
An out-of-bounds (OOB) memory access flaw was found in fbcongetfont() in drivers/video/fbdev/core/fbcon.c in fbcon driver module in the Linux kernel. A bound check failure allows a local attacker with special user privilege to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to integrity and system availability.
An out-of-bounds (OOB) memory access flaw was found in fbcongetfont() in drivers/video/fbdev/core/fbcon.c in fbcon driver module in the Linux kernel. A bound check failure may allow a local attacker with special user privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
Reference: https://syzkaller.appspot.com/bug?id=08b8be45afea11888776f897895aef9ad1c3ecfd
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-28915?
CVE-2020-28915 is classified as a medium severity vulnerability due to its potential for local exploitation to read kernel memory.
How do I fix CVE-2020-28915?
To remediate CVE-2020-28915, upgrade to kernel versions 5.10.223-1, 5.10.226-1, or any later versions listed in the advisory.
What kind of vulnerability is CVE-2020-28915?
CVE-2020-28915 is a buffer over-read vulnerability that occurs at the framebuffer layer in the Linux kernel.
Which Linux kernel versions are affected by CVE-2020-28915?
CVE-2020-28915 affects Linux kernel versions prior to 5.8.15.
Can CVE-2020-28915 be exploited remotely?
CVE-2020-28915 cannot be exploited remotely, as it requires local access to the system.