oss-sec mailing list archives

CVE-2020-35519 Linux kernel: x25_bind out-of-bounds read


From: Rohit Keshri <rkeshri () redhat com>
Date: Thu, 18 Mar 2021 01:20:18 +0530

Hello Team,

An out-of-bounds (OOB) memory access flaw was found in x25_bind in
net/x25/af_x25.c in the Linux kernel. A bounds check failure allows a local
attacker with a user account on the system to gain access to out-of-bounds
memory, leading to a system crash or a leak of internal kernel information.
The highest threat from this vulnerability is to confidentiality,
integrity, as well as system availability.

'CVE-2020-35519' was assigned by Red Hat.


Regards,
..
Rohit Keshri / Red Hat Product Security Team
PGP: OX01BC 858A 07B7 15C8 EF33 BFE2 2EEB 0CBC 84A4 4C2D

secalert () redhat com for urgent response

Current thread: