cbcvebase.
CVE-2020-10732
published 2020-06-12

CVE-2020-10732: A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and…

PriorityP419medium4.4CVSS 3.1
AVLACLPRLUINSUCLINAL
EPSS
0.62%
45.6th percentile
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.

Affected

24 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 5.6.14-2 (bookworm)linux 5.6.14-2 (bookworm)
googleandroid
linuxlinux_kernel< 3.16.853.16.85
linuxlinux_kernel>= 0 < 5.6.14-25.6.14-2
linuxlinux_kernel>= 0 < 5.6.14-25.6.14-2
linuxlinux_kernel>= 0 < 5.6.14-25.6.14-2
linuxlinux_kernel>= 0 < 5.6.14-25.6.14-2
linuxlinux_kernel>= 0 < 4.4.0-186.2164.4.0-186.216
linuxlinux_kernel>= 0 < 4.15.0-115.1164.15.0-115.116
linuxlinux_kernel>= 0 < 5.4.0-40.445.4.0-40.44
linuxlinux_kernel>= 4.14 < 4.14.1834.14.183
linuxlinux_kernel>= 4.19 < 4.19.1264.19.126
linuxlinux_kernel>= 4.4 < 4.4.2264.4.226
linuxlinux_kernel>= 4.9 < 4.9.2264.9.226
linuxlinux_kernel>= 5.4 < 5.4.445.4.44
linuxlinux_kernel>= 5.6 < 5.6.165.6.16
linux_kernelkernel
netappactive_iq_unified_manager>= 9.5
opensuseleap
opensuseleap

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.