cbcvebase.
CVE-2020-14356
published 2020-08-19

CVE-2020-14356: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.97%
58.1th percentile
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.7.10-1 (bookworm)linux 5.7.10-1 (bookworm)
debianlinux
linuxlinux_kernel>= 0 < 5.7.10-15.7.10-1
linuxlinux_kernel>= 0 < 5.7.10-15.7.10-1
linuxlinux_kernel>= 0 < 5.7.10-15.7.10-1
linuxlinux_kernel>= 0 < 5.7.10-15.7.10-1
linuxlinux_kernel>= 0 < 4.15.0-118.1194.15.0-118.119
linuxlinux_kernel>= 0 < 5.4.0-45.495.4.0-45.49
linuxlinux_kernel>= 4.10 < 4.14.1894.14.189
linuxlinux_kernel>= 4.14 < 4.14.1944.14.194
linuxlinux_kernel>= 4.15 < 4.19.1344.19.134
linuxlinux_kernel>= 4.19 < 4.19.1404.19.140
linuxlinux_kernel>= 4.20 < 5.4.535.4.53
linuxlinux_kernel>= 4.5 < 4.9.2314.9.231
linuxlinux_kernel>= 4.9.0 < 4.9.2334.9.233
linuxlinux_kernel>= 5.5 < 5.7.105.7.10
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-3_on_cbl_mariner_1.0
opensuseleap

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.