A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
2020-12-02T01:15:12.607
2024-11-21T05:18:22.093
Modified
CVSSv3.1: 4.1 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 5.10 | Yes |
Operating System | linux | linux_kernel | 5.10 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Application | starwindsoftware | starwind_virtual_san | v8 | Yes |
Application | starwindsoftware | starwind_virtual_san | v8 | Yes |
Application | starwindsoftware | starwind_virtual_san | v8 | Yes |
Application | starwindsoftware | starwind_virtual_san | v8 | Yes |
Application | starwindsoftware | starwind_virtual_san | v8 | Yes |
Application | starwindsoftware | starwind_virtual_san | v8 | Yes |