CVE-2020-28588
published 2021-05-10CVE-2020-28588: An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
1.10%
62.5th percentile
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.9.15-1 (bookworm) | linux 5.9.15-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.9.15-1 | 5.9.15-1 |
| linux | linux_kernel | >= 0 < 5.9.15-1 | 5.9.15-1 |
| linux | linux_kernel | >= 0 < 5.9.15-1 | 5.9.15-1 |
| linux | linux_kernel | >= 0 < 5.9.15-1 | 5.9.15-1 |
| linux | linux_kernel | >= 0 < 5.4.0-66.74 | 5.4.0-66.74 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-02-25·CVSS 7.8
CVE-2020-25669 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Bodong Zhao discovered a use-after-free in the Sun keyboard driver
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2020-25669)
It was discovered that the jfs file system implementation in the Linux
kernel contained an out-of-bounds read vulnerability. A local attacker
could use this to possibly cause a denial of service (system crash).
(CVE-2020-27815)
Shisong Qin and Bodong Zhao discovered that Speakup screen reader driver in
the Linux kernel did not correctly handle setting line discipline in some
situations. A local attacker could use this to cause a denial of service
(system crash). (CVE-2020-2
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-02-25·CVSS 4.1
CVE-2020-25704 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Bodong Zhao discovered a use-after-free in the Sun keyboard driver
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2020-25669)
Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2021-02-25·CVSS 5.4
CVE-2020-27152 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)
It was di
Red Hat
kernel: information leak in the syscall implementation on 32-bit systems
vendor_redhat·2020-12-03·CVSS 5.5
CVE-2020-28588 [MEDIUM] CWE-908 kernel: information leak in the syscall implementation on 32-bit systems
kernel: information leak in the syscall implementation on 32-bit systems
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
A flaw read uninitialized values in the Linux kernel syscall implementation on 32 bit-systems was found in the way user reading /proc/self/syscall.
A local user could use this flaw to read three 64 bits uninitialized values, but cannot control which values. The highest thre
Debian
CVE-2020-28588: linux - An information disclosure vulnerability exists in the /proc/pid/syscall function...
vendor_debian·2020·CVSS 5.5
CVE-2020-28588 [MEDIUM] CVE-2020-28588: linux - An information disclosure vulnerability exists in the /proc/pid/syscall function...
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
Scope: local
bookworm: resolved (fixed in 5.9.15-1)
bullseye: resolved (fixed in 5.9.15-1)
forky: resolved (fixed in 5.9.15-1)
sid: resolved (fixed in 5.9.15-1)
trixie: resolved (fixed in 5.9.15-1)
GHSA
GHSA-xxv6-ggg8-68mq: An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5
ghsa_unreviewed·2022-05-24
CVE-2020-28588 [MEDIUM] CWE-681 GHSA-xxv6-ggg8-68mq: An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
OSV
CVE-2020-28588: An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5
osv·2021-05-10·CVSS 5.5
CVE-2020-28588 [MEDIUM] CVE-2020-28588: An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities
osv·2021-02-25·CVSS 4.1
CVE-2020-25656 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Bodong Zhao discovered a use-after-free in the Sun keyboard driver
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2020-25669)
Kiyin (尹亮) discovered that the perf subsystem in the Linu
OSV
linux-oem-5.6 vulnerabilities
osv·2021-02-25·CVSS 5.4
CVE-2020-10135 [MEDIUM] linux-oem-5.6 vulnerabilities
linux-oem-5.6 vulnerabilities
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)
It was discovered that the block layer implementation in the Linux kernel
did not prope
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-ra
osv·2021-02-25·CVSS 7.8
CVE-2020-25669 [HIGH] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-ra
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
Bodong Zhao discovered a use-after-free in the Sun keyboard driver
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2020-25669)
It was discovered that the jfs file system implementation in the Linux
kernel contained an out-of-bounds read vulnerability. A local attacker
could use this to possibly cause a denial of service (system crash).
(CVE-2020-27815)
Shisong Qin and Bodong Zhao discovered that Speakup screen reader driver in
the Linux kernel did not correctly hand
Kernel
lib/syscall: fix syscall registers retrieval on 32-bit platforms
kernel_security·2020-11-30·CVSS 5.5
CVE-2020-28588 [MEDIUM] lib/syscall: fix syscall registers retrieval on 32-bit platforms
lib/syscall: fix syscall registers retrieval on 32-bit platforms
Lilith >_> and Claudio Bozzato of Cisco Talos security team reported
that collect_syscall() improperly casts the syscall registers to 64-bit
values leaking the uninitialized last 24 bytes on 32-bit platforms, that
are visible in /proc/self/syscall.
The cause is that info->data.args are u64 while syscall_get_arguments()
uses longs, as hinted by the bogus pointer cast in the function.
Let's just proceed like the other call places, by retrieving the
registers into an array of longs before assigning them to the caller's
array. This was successfully tested on x86_64, i386 and ppc32.
Reference: CVE-2020-28588, TALOS-2020-1211
Fixes: 631b7abacd02 ("ptrace: Remove maxargs from task_current_syscall()")
Cc: Greg KH
Reviewed-by: Kee
No detection rules found.
No public exploits indexed.
Talos
Threat Source Newsletter (May 6, 2021)
blogs_talos·2021-05-06
Threat Source Newsletter (May 6, 2021)
## Threat Source Newsletter (May 6, 2021)
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
COVID-19 has changed everything about our lives — no surprise there. So it also shouldn't be shocking that it's changing the way Americans view Tax Day this year.
The deadline to file taxes is about a month later than usual and is now only 11 days away. Attackers have jumped on this opportunity to create new malware campaigns centered around taxes and COVID-19. You don't want to miss the latest Talos Takes episode where we talk about scams around supposed rewards for receiving your COVID vaccine, promises of better tax returns, and everything else you could think of with "taxes" in the subject line of a spam email.
## Upcoming public engagements with Talos
Title: Cisco Secure
Talos
Threat Source Newsletter (May 6, 2021)
blogs_talos·2021-05-06
Threat Source Newsletter (May 6, 2021)
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
COVID-19 has changed everything about our lives — no surprise there. So it also shouldn't be shocking that it's changing the way Americans view Tax Day this year.
The deadline to file taxes is about a month later than usual and is now only 11 days away. Attackers have jumped on this opportunity to create new malware campaigns centered around taxes and COVID-19. You don't want to miss the latest Talos Takes episode where we talk about scams around supposed rewards for receiving your COVID vaccine, promises of better tax returns, and everything else you could think of with "taxes" in the subject line of a spam email.
## Upcoming public engagements with Talos
Title:Cisco Secure at RSA 2021
Date: May 17 - 20
Overview: Co
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
blogs_talos·2021-05-06·CVSS 5.5
CVE-2020-28588 [MEDIUM] Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
## Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a use-after-free vulnerability in the Foxit PDF Reader.
Foxit PDF Reader is one of the most popular PDF document readers currently available. As a complete and feature-rich PDF reader, it supports JavaScript for interactive documents and dynamic forms.
TALOS-2021-1287 (CVE-2020-28588) is a use-after-free vulnerability that exists in the PDF Reader that could lead to an adversary gaining the ability to execute arbitrary code on the victim machine. An attacker needs to trick a user into opening a specially crafted, malicious PDF to exploit this vulnerability. The vulnerability specifically exists
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
blogs_talos·2021-05-06·CVSS 5.5
CVE-2020-28588 [MEDIUM] Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a use-after-free vulnerability in the Foxit PDF Reader.
Foxit PDF Reader is one of the most popular PDF document readers currently available. As a complete and feature-rich PDF reader, it supports JavaScript for interactive documents and dynamic forms.
TALOS-2021-1287 (CVE-2020-28588) is a use-after-free vulnerability that exists in the PDF Reader that could lead to an adversary gaining the ability to execute arbitrary code on the victim machine. An attacker needs to trick a user into opening a specially crafted, malicious PDF to exploit this vulnerability. The vulnerability specifically exists in the way Foxit PDF Reader handles certain annotation types.
Cisco Talos wo
Talos
Vulnerability Spotlight: Information disclosure vulnerability in the Linux Kernel
blogs_talos·2021-04-27·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Information disclosure vulnerability in the Linux Kernel
## Vulnerability Spotlight: Information disclosure vulnerability in the Linux Kernel
Lilith >_> and Claudio Bozzato of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an information disclosure vulnerability in the Linux Kernel.
The Linux Kernel is the free and open-source core of Unix-like operating systems. This vulnerability specifically exists in the /proc/pid/syscall functionality of 32-bit ARM devices running Linux.
TALOS-2020-1211 (CVE-2020-28588) is an information disclosure vulnerability that could allow an attacker to view Kernel stack memory . We first discovered this issue on an Azure Sphere device (version 20.10), a 32-bit ARM device that runs a patched Linux kernel. An attacker could exploit this vulnerability by reading /pro
Talos
Vulnerability Spotlight: Information disclosure vulnerability in the Linux Kernel
blogs_talos·2021-04-27·CVSS 5.5
CVE-2020-28588 [MEDIUM] Vulnerability Spotlight: Information disclosure vulnerability in the Linux Kernel
Lilith >_> and Claudio Bozzato of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an information disclosure vulnerability in the Linux Kernel.
The Linux Kernel is the free and open-source core of Unix-like operating systems. This vulnerability specifically exists in the /proc/pid/syscall functionality of 32-bit ARM devices running Linux.
TALOS-2020-1211 (CVE-2020-28588) is an information disclosure vulnerability that could allow an attacker to view Kernel stack memory . We first discovered this issue on an Azure Sphere device (version 20.10), a 32-bit ARM device that runs a patched Linux kernel. An attacker could exploit this vulnerability by reading /proc//syscall, a legitimate Linux operating system file — making it impossible to detect
2021-05-10
Published