PT-2022-37687 · Openeuler · Kernel

CVE-2020-1852

·

Published

2022-06-29

·

Updated

2022-06-29

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The Linux Kernel, the operating system core itself.
Security Fix(es):
NFC: netlink: fix sleep in atomic bug when firmware download timeout(CVE-2022-1975)
In various methods of kernel base drivers, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-182388481References: Upstream kernel(CVE-2022-20166)
A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86 emulate insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.(CVE-2022-1852)

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-1852
OESA-2022-1730

Affected Products

Kernel