SB2019072614 - Buffer overflow in Linux kernel
Published: July 26, 2019 Updated: July 31, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2018-20854)
The vulnerability allows a local attacker to access sensitive information on a targeted system.
The vulnerability exists due to improper memory operations performed by the "phy-ocelot-serdes.c" file. A local authenticated attacker can make a malicious request, cause an off-by-one out-of-bounds read condition and access sensitive information on the targeted system.
Remediation
Install update from vendor's website.