Back

HIGH

kernel: integer overflow in k_ascii() in drivers/tty/vt/keyboard.c

Published Jun 9, 2020

Description

An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case.

Affected products

Remediation

Red Hat statement

No code depends on this integer overflow so it is unlikely that the vulnerability can be used for anything apart from crashing the system. The impact has been reduced to Moderate from Important based on this analysis.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 9, 2020
Updated Aug 4, 2024
Reserved Jun 9, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 22, 2020
ENISA EUVD
Assigner mitre
Published Jun 9, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-6145