CVE-2020-10067
Summary
| CVE | CVE-2020-10067 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-11 23:15:00 UTC |
| Updated | 2020-06-05 18:15:00 UTC |
| Description | A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers. The impact would depend on the underlying system call and can range from denial of service to information leak to memory corruption resulting in code execution within the kernel. See NCC-ZEP-005 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Zephyrproject | Zephyr | 1.14.1 | All | All | All |
| Operating System | Zephyrproject | Zephyr | 2.1.0 | All | All | All |
| Operating System | Zephyrproject | Zephyr | 1.14.1 | All | All | All |
| Operating System | Zephyrproject | Zephyr | 2.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [ZEPSEC-27] Integer Overflow In is_in_region Allows User Thread To Access Kernel Memory - Zephyr Project Security Issues | MISC | zephyrprojectsec.atlassian.net | Third Party Advisory |
| Vulnerabilities — Zephyr Project Documentation | MISC | docs.zephyrproject.org | |
| Backport v1.14: syscalls: arm: Fix possible overflow in is_in_region function by ceolin · Pull Request #23653 · zephyrproject-rtos/zephyr · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Backport v2.1: syscalls: arm: Fix possible overflow in is_in_region function by ceolin · Pull Request #23654 · zephyrproject-rtos/zephyr · GitHub | MISC | github.com | Patch, Third Party Advisory |
| syscalls: arm: Fix possible overflow in is_in_region function by ceolin · Pull Request #23239 · zephyrproject-rtos/zephyr · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: NCC Group for report
There are currently no legacy QID mappings associated with this CVE.