ZeroHour

CVE-2020-27825

CVSS 3.1
5.7 medium
EPSS
<1%p20
Published
()
Modified
Description

A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.

Vendors
linuxredhatdebiannetapp
Products
linux kernel, enterprise linux, enterprise mrg, debian linux, cloud backup, solidfire baseboard management controller firmware, h410c firmware
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.