CVE-2020-0427
published 2020-09-17CVE-2020-0427: In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.47%
38.3th percentile
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.4.8-1 (bookworm) | linux 5.4.8-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.4.8-1 | 5.4.8-1 |
| linux | linux_kernel | >= 0 < 5.4.8-1 | 5.4.8-1 |
| linux | linux_kernel | >= 0 < 5.4.8-1 | 5.4.8-1 |
| linux | linux_kernel | >= 0 < 5.4.8-1 | 5.4.8-1 |
| linux | linux_kernel | >= 0 < 4.4.0-197.229 | 4.4.0-197.229 |
| linux | linux_kernel | >= 0 < 4.4.0-262.296 | 4.4.0-262.296 |
| linux | linux_kernel | >= 0 < 4.15.0-132.136 | 4.15.0-132.136 |
| linux | linux_kernel | >= 0 < 5.4.0-62.70 | 5.4.0-62.70 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| starwindsoftware | starwind_virtual_san | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2021-01-26·CVSS 5.5
CVE-2020-28374 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Elena Petrova discovered that the pin controller device tree implementation
in the Linux kernel did not properly handle string references. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-0427)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux
kernel did not properly initialize memory in some situations. A physically
proximate remote attacker could use this to expose sensitive information
(kernel memory). (CVE-2020-12352)
It was discovered that the GENEVE tunnel implementation in the Linux kernel
when combined with IPSec did not properly select IP routes in some
situations. An attacker could use this to expose sensitive i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-12-02·CVSS 5.5
CVE-2020-14351 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Elena Petrova discovered that the pin controller device tree implementation
in the Linux kernel did not properly handle string references. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-0427)
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Andy Nguyen discovered that the Bluetooth A2MP implementation in
Red Hat
kernel: out-of-bounds reads in pinctrl subsystem.
vendor_redhat·2020-11-22·CVSS 5.5
CVE-2020-0427 [MEDIUM] CWE-200 kernel: out-of-bounds reads in pinctrl subsystem.
kernel: out-of-bounds reads in pinctrl subsystem.
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
A flaw was found in the Linux pinctrl system. It is possible to trigger an of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or
Debian
CVE-2020-0427: linux - In create_pinctrl of core.c, there is a possible out of bounds read due to a use...
vendor_debian·2020·CVSS 5.5
CVE-2020-0427 [MEDIUM] CVE-2020-0427: linux - In create_pinctrl of core.c, there is a possible out of bounds read due to a use...
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
Scope: local
bookworm: resolved (fixed in 5.4.8-1)
bullseye: resolved (fixed in 5.4.8-1)
forky: resolved (fixed in 5.4.8-1)
sid: resolved (fixed in 5.4.8-1)
trixie: resolved (fixed in 5.4.8-1)
GHSA
GHSA-cmm7-9576-wh39: In create_pinctrl of core
ghsa_unreviewed·2022-05-24
CVE-2020-0427 [MEDIUM] CWE-125 GHSA-cmm7-9576-wh39: In create_pinctrl of core
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
OSV
Kernel Live Patch Security Notice
osv·2021-01-26·CVSS 5.5
CVE-2020-0427 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Elena Petrova discovered that the pin controller device tree implementation
in the Linux kernel did not properly handle string references. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-0427)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux
kernel did not properly initialize memory in some situations. A physically
proximate remote attacker could use this to expose sensitive information
(kernel memory). (CVE-2020-12352)
It was discovered that the GENEVE tunnel implementation in the Linux kernel
when combined with IPSec did not properly select IP routes in some
situations. An attacker could use this to expose sensitive information
(unencrypted network traffic). (CVE-2020-25645)
It was
OSV
linux, linux-aws, linux-azure, linux-kvm, linux-lts-trusty, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-12-02·CVSS 5.5
CVE-2020-0427 [MEDIUM] linux, linux-aws, linux-azure, linux-kvm, linux-lts-trusty, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-azure, linux-kvm, linux-lts-trusty, linux-raspi2, linux-snapdragon vulnerabilities
Elena Petrova discovered that the pin controller device tree implementation
in the Linux kernel did not properly handle string references. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-0427)
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Andy Nguyen discovered that the Bluetooth A2MP implementatio
OSV
CVE-2020-0427: In create_pinctrl of core
osv·2020-09-17·CVSS 5.5
CVE-2020-0427 [MEDIUM] CVE-2020-0427: In create_pinctrl of core
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.htmlhttp://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00027.htmlhttps://source.android.com/security/bulletin/pixel/2020-09-01https://www.starwindsoftware.com/security/sw-20210325-0005/http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.htmlhttp://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00027.htmlhttps://source.android.com/security/bulletin/pixel/2020-09-01https://www.starwindsoftware.com/security/sw-20210325-0005/
2020-09-17
Published