CVE-2020-10732

Advisory lineage Upstream: 0 Downstream: 33
Modified
Published: 12 Jun 2020, 00:00
Last modified:04 Aug 2024, 11:14

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.4 MEDIUM
v3.1 (nvd)
EPSS Score
0.04% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Jun 2020, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 11:14
Last Modified
Vulnerability information updated

Description

A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.

CVSS Metrics

  • v3.1LOWScore: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
  • v2.0LOWScore: 3.6AV:L/AC:L/Au:N/C:P/I:N/A:P

EPSS Trends

Current EPSS score: 0.04% Percentile: 12%

Techniques & Countermeasures

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 20.04

  • linux kernelkernel

    introduced in commit 4206d3aa1978e44f58bfa4e1c9d8d35cbf19c187

  • linuxlinux_kernel

    < 3.16.85 | ≥ 4.4, < 4.4.226 | ≥ 4.9, < 4.9.226 | ≥ 4.14, < 4.14.183 | ≥ 4.19, < 4.19.126 | ≥ 5.4, < 5.4.44 | ≥ 5.6, < 5.6.16

  • netappactive_iq_unified_manager

    ≥ 9.5

  • netappaff_8300_firmware

    na

  • netappaff_8700_firmware

    na

  • netappaff_a400_firmware

    na

  • netappaff_a700_firmware

    na

  • netapph300e_firmware

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e_firmware

    na

  • netapph500s_firmware

    na

  • netapph700e_firmware

    na

  • netapph700s_firmware

    na

  • netapphci_management_node

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • opensuseleap

    15.1 | 15.2

References (14)