CVE-2020-28915
Summary
| CVE | CVE-2020-28915 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-18 08:15:00 UTC |
| Updated | 2020-12-15 19:52:00 UTC |
| Description | A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| KASAN: global-out-of-bounds Read in fbcon_get_font |
MISC |
syzkaller.appspot.com |
Patch, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
Patch, Vendor Advisory |
| cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.15 |
MISC |
cdn.kernel.org |
Release Notes, Vendor Advisory |
| Bug 1178886 – VUL-0: CVE-2020-28915: kernel-source: kernel buffer overflow read in font handling |
MISC |
bugzilla.suse.com |
Issue Tracking, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159962 Oracle Enterprise Linux Security Update for kernel (ELSA-2022-5316)
- 240528 Red Hat Update for kernel-rt (RHSA-2022:5344)
- 240534 Red Hat Update for kernel (RHSA-2022:5316)
- 353100 Amazon Linux Security Advisory for kernel : ALAC2012-2021-024
- 353101 Amazon Linux Security Advisory for kmod-mlx5 : ALAC2012-2021-025
- 353102 Amazon Linux Security Advisory for kmod-sfc : ALAC2012-2021-026
- 375284 EulerOS Security Update for kernel (EulerOS-SA-2021-1311)
- 390217 Oracle Managed Virtualization (VM) Server for x86 Security Update for Unbreakable Enterprise kernel (OVMSA-2021-0001)
- 390234 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0001)
- 670185 EulerOS Security Update for kernel (EulerOS-SA-2021-1684)
- 750376 OpenSUSE Security Update for RT kernel (openSUSE-SU-2021:0242-1)
- 750488 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2020:2260-1)
- 750518 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2020:2161-1)
- 750568 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2020:2034-1)
- 900040 CBL-Mariner Linux Security Update for kernel 5.4.91
- 903331 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3630)
- 906170 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3630-1)
- 940589 AlmaLinux Security Update for kernel-rt (ALSA-2022:5344)
- 940593 AlmaLinux Security Update for kernel (ALSA-2022:5316)
- 960258 Rocky Linux Security Update for kernel-rt (RLSA-2022:5344)
- 960418 Rocky Linux Security Update for kernel (RLSA-2022:5316)