CVE-2020-28941 - log back

CVE-2020-28941 edited at 19 Nov 2020 17:42:43
Notes
- The affected driver is built as module which is not loaded by default.
CVE-2020-28941 edited at 19 Nov 2020 17:42:32
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Denial of service
Description
+ An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.
References
+ https://www.openwall.com/lists/oss-security/2020/11/19/3
+ https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d4122754442799187d5d537a9c039a49a67e57f1
Notes
+ The affected driver is built as module which is not loaded by default.
CVE-2020-28941 created at 19 Nov 2020 17:38:29