CVE-2020-27830NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
OSV7.8OSV4.1
EPSS
0.1%
top 65.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel< 5.9.14
Debianlinux/linux_kernel< 5.9.15-1+3
Ubuntulinux/linux_kernel< 4.15.0-136.140+1
CVEListV5linux/linux_kernelkernel 5.9.14
debiandebian/linux< linux 5.9.15-1 (bookworm)

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

6
GHSA
GHSA-w2vj-j8wh-3c7w: A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whethe2022-05-24
OSV
CVE-2020-27830: A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whethe2021-05-13
OSV
linux-oem-5.6 vulnerabilities2021-04-13
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities2021-02-25
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabil2021-02-25

📋Vendor Advisories

6
Ubuntu
Linux kernel (OEM) vulnerabilities2021-04-13
Ubuntu
Linux kernel vulnerabilities2021-02-25
Ubuntu
Linux kernel vulnerabilities2021-02-25
Ubuntu
Linux kernel vulnerabilities2021-02-25
Red Hat
kernel: null pointer dereference in in spk_ttyio_receive_buf22020-11-30
CVE-2020-27830 — NULL Pointer Dereference in Kernel | cvebase