SB2020091807 - Information disclosure in Linux kernel
Published: September 18, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-10773)
The vulnerability allows a local privileged user to gain access to sensitive information.
A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. A local privileges user can gain access to sensitive data in the memory.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.