cbcvebase.
CVE-2020-28915
published 2020-11-18

CVE-2020-28915: A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka…

PriorityP418medium5.8CVSS 3.1
AVPACLPRHUINSUCLIHAH
EPSS
0.37%
30.2th percentile
A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.9.1-1 (bookworm)linux 5.9.1-1 (bookworm)
linuxlinux_kernel< 5.8.155.8.15
linuxlinux_kernel>= 0 < 5.9.1-15.9.1-1
linuxlinux_kernel>= 0 < 5.9.1-15.9.1-1
linuxlinux_kernel>= 0 < 5.9.1-15.9.1-1
linuxlinux_kernel>= 0 < 5.9.1-15.9.1-1
linuxlinux_kernel>= 0 < 4.4.0-197.2294.4.0-197.229
linuxlinux_kernel>= 0 < 4.15.0-128.1314.15.0-128.131
linuxlinux_kernel>= 0 < 4.15.0-126.1294.15.0-126.129
linuxlinux_kernel>= 0 < 5.4.0-58.645.4.0-58.64
linuxlinux_kernel>= 0 < 5.4.0-56.625.4.0-56.62
msrccm1_kernel_5.4.91-1_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.15.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
nvdv2.06.1MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.8MEDIUM
vendor_msrc5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.