kernel: integer overflow in k_ascii() in drivers/tty/vt/keyboard.c
Published Jun 9, 2020
7.8
HIGHCVSS 3.1
EPSS 0.57%
Description
An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case.
Affected products
No data.
Configuration 1
- < 4.4.227
- ≥ 4.5 · < 4.9.227
- ≥ 4.10 · < 4.14.184
- ≥ 4.15 · < 4.19.128
- ≥ 4.20 · < 5.4.46
- ≥ 5.5 · < 5.6.18
- ≥ 5.7 · < 5.7.2
Configuration 2
- 9.0
Configuration 3
- 14.04
- 16.04
- 18.04
- 20.04
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.9.1.el8
Fixed · RHSA-2022:1988
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-372.9.1.rt7.166.el8
Fixed · RHSA-2022:1975
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-alt
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.9.1.el8 | Fixed | RHSA-2022:1988 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-372.9.1.rt7.166.el8 | Fixed | RHSA-2022:1975 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
No code depends on this integer overflow so it is unlikely that the vulnerability can be used for anything apart from crashing the system. The impact has been reduced to Moderate from Important based on this analysis.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-13974 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2016169 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-6145 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=dad0bf9ce93fa40b667eccd3306783f4db4b932b x_refsource_MISCVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b86dab054059b970111b5516ae548efaae5b3aae x_refsource_MISCPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00019.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lkml.org/lkml/2020/3/22/482 x_refsource_MISCExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-13974
- https://usn.ubuntu.com/4427-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4439-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4440-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4483-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4485-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-13974
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.