CVE-2020-14331
Summary
| CVE | CVE-2020-14331 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-15 19:15:00 UTC |
| Updated | 2023-02-12 23:40:00 UTC |
| Description | A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2420-2] linux regression update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| 1858679 – (CVE-2020-14331) CVE-2020-14331 kernel: kernel: buffer over write in vgacon_scroll |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| [SECURITY] [DLA 2385-1] linux-4.19 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| linux-kernel - [PATCH] vgacon: fix out of bounds write to the scrollback buffer |
MISC |
lists.openwall.net |
Mailing List, Patch, Third Party Advisory |
| oss-security - [CVE-2020-14331] Linux Kernel: buffer over write in
vgacon_scrollback_update |
MISC |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2420-1] linux security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174728 SUSE Enterprise Linux Security update for the Linux Kernel (SUSE-SU-2020:2122-1)
- 353100 Amazon Linux Security Advisory for kernel : ALAC2012-2021-024
- 353101 Amazon Linux Security Advisory for kmod-mlx5 : ALAC2012-2021-025
- 353102 Amazon Linux Security Advisory for kmod-sfc : ALAC2012-2021-026
- 378473 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0021)
- 750376 OpenSUSE Security Update for RT kernel (openSUSE-SU-2021:0242-1)
- 900076 CBL-Mariner Linux Security Update for kernel 5.4.91
- 903374 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3473)
- 906198 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3473-1)