漏洞信息详情
Linux kernel 缓冲区错误漏洞
漏洞简介
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。
Linux kernel 5.8.15之前版本存在安全漏洞,该漏洞源于fbcon代码中的缓冲区over-read (at the framebuffer layer)可以被本地攻击者用来读取内核内存.
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.15
参考网址
来源:MISC
链接:https://bugzilla.suse.com/show_bug.cgi?id=1178886
来源:MISC
链接:https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6735b4632def0640dbdf4eb9f99816aca18c4f16
来源:MISC
链接:https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.15
来源:MISC
链接:https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5af08640795b2b9a940c9266c0260455377ae262
来源:MISC
链接:https://syzkaller.appspot.com/bug?id=08b8be45afea11888776f897895aef9ad1c3ecfd
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4284/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4391/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0717
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-28915
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0589
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4377/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4410/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160305/Ubuntu-Security-Notice-USN-4657-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4275/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Linux-kernel-out-of-bounds-memory-reading-via-fbcon-get-font-33932
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4341/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160472/Ubuntu-Security-Notice-USN-4659-2.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161556/Ubuntu-Security-Notice-USN-4752-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160342/Ubuntu-Security-Notice-USN-4660-1.html
受影响实体
暂无
补丁
- Linux kernel 缓冲区错误漏洞的修复措施<!--2020-11-18-->
还没有评论,来说两句吧...