Tracker / CVE-2020-11494
CVE-2020-11494
Medium 4.4
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| linux | linux_kernel · 3.16 → 5.6.2 |
| opensuse | leap |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.