CVE-2020-9897
published 2021-10-28CVE-2020-9897: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.91%
55.8th percentile
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_14.2_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.2 | 14.2 |
| apple | ipados | < 14.2 | 14.2 |
| apple | iphone_os | < 14.2 | 14.2 |
| apple | macos | < 11.0.1 | 11.0.1 |
| apple | macos | >= unspecified < 11.0 | 11.0 |
| linux | linux_kernel | >= 6.4.0 < 6.4.4 | 6.4.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2020-9897: iOS 14.2 and iPadOS 14.2
vendor_apple·2020-11-05·CVSS 7.8
CVE-2020-9897 [HIGH] CVE-2020-9897: iOS 14.2 and iPadOS 14.2
Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2
Product: iOS 14.2 and iPadOS
Version: 14.2
CVE: CVE-2020-9897
Component: CoreGraphics
Impact: Processing a maliciously crafted PDF may lead to arbitrary code execution
Description: An out-of-bounds write was addressed with improved input validation.
OSV
vduse: fix NULL pointer dereference
osv·2025-12-30
CVE-2023-54291 vduse: fix NULL pointer dereference
vduse: fix NULL pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
vduse: fix NULL pointer dereference
vduse_vdpa_set_vq_affinity callback can be called
with NULL value as cpu_mask when deleting the vduse
device.
This patch resets virtqueue's IRQ affinity mask value
to set all CPUs instead of dereferencing NULL cpu_mask.
[ 4760.952149] BUG: kernel NULL pointer dereference, address: 0000000000000000
[ 4760.959110] #PF: supervisor read access in kernel mode
[ 4760.964247] #PF: error_code(0x0000) - not-present page
[ 4760.969385] PGD 0 P4D 0
[ 4760.971927] Oops: 0000 [#1] PREEMPT SMP PTI
[ 4760.976112] CPU: 13 PID: 2346 Comm: vdpa Not tainted 6.4.0-rc6+ #4
[ 4760.982291] Hardware name: Dell Inc. PowerEdge R640/0W23H8, BIOS 2.8.1 06/26/2020
[ 4760.9897
GHSA
GHSA-h4f4-qrhw-qpwr: An out-of-bounds write was addressed with improved input validation
ghsa_unreviewed·2022-05-24
CVE-2020-9897 [HIGH] CWE-787 GHSA-h4f4-qrhw-qpwr: An out-of-bounds write was addressed with improved input validation
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-28
Published