CVE-2020-14390Out-of-bounds Write in Kernel

CWE-787Out-of-bounds Write20 documents8 sources
Severity
5.6MEDIUMNVD
OSV7.8OSV5.5
EPSS
0.2%
top 62.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 24

Description

A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:HExploitability: 0.8 | Impact: 4.7

Affected Packages6 packages

NVDlinux/linux_kernel2.2.35.9.0+1
Debianlinux/linux_kernel< 5.8.10-1+3
Ubuntulinux/linux_kernel< 4.4.0-197.229+4
CVEListV5linux/linux_kernelLinux kernel versions before 5.9-rc6
debiandebian/linux< linux 5.8.10-1 (bookworm)

Also affects: Debian Linux 9.0

🔴Vulnerability Details

8
GHSA
GHSA-h8pg-xg8h-5pgp: A flaw was found in the Linux kernel in versions from 22022-05-24
OSV
linux-oem-5.6 vulnerabilities2021-04-13
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 regression2020-12-13
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-snapdragon regression2020-12-13
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities2020-12-03

📋Vendor Advisories

9
Ubuntu
Linux kernel (OEM) vulnerabilities2021-04-13
Ubuntu
Linux kernel regression2020-12-13
Ubuntu
Linux kernel regression2020-12-13
Ubuntu
Linux kernel vulnerabilities2020-12-03
Ubuntu
Linux kernel vulnerabilities2020-12-03

💬Community

2
Bugzilla
CVE-2020-14390 kernel: out-of-bounds write in fbcon_redraw_softback [fedora-all]2020-09-17
Bugzilla
CVE-2020-14390 kernel: out-of-bounds write in fbcon_redraw_softback2020-09-08
CVE-2020-14390 — Out-of-bounds Write in Linux Kernel | cvebase