CVE-2020-15437 PUBLISHED

The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:serial8250_isa_init_ports() that allows local users to cause a denial of service by using the p->serial_in pointer which uninitialized.

EPSS 0.04% · 13.1th percentile

Risk Scores

EPSS Score
0.04%
13.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-azure-fips0, 5.4.0-1022.22+fips1
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1039.41~16.04.1, 4.15.0-1040.42~16.04.1, 4.15.0-1041.43~16.04.1
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1077.82, 4.4.0-1133.141, 4.4.0-1134.142
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1075.79, 4.4.0-1076.80, 0
Ubuntu:16.04:LTSlinux-oracle4.15.0-1039.43~16.04.1, 4.15.0-1021.23~16.04.1, 4.15.0-1022.25~16.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips0, 4.15.0-1002.2
Ubuntu:20.04:LTSlinux-gcp5.4.0-1007.7, 5.4.0-1021.21, 5.4.0-1019.19
Ubuntu:16.04:LTSlinux-hwe-edge4.13.0-17.20~16.04.1, 4.10.0-14.16~16.04.1, 4.10.0-19.21~16.04.1
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.150, 5.15.0-1103.112~20.04.1.1, 5.15.0-1102.111~20.04.1.1
Ubuntu:18.04:LTSlinux-kvm4.15.0-1002.2, 4.15.0-1071.72, 4.15.0-1069.70
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1066.69, 4.15.0-1064.67, 4.15.0-1063.66
Ubuntu:16.04:LTSlinux-hwe4.15.0-99.100~16.04.1, 4.15.0-101.102~16.04.1, 4.15.0-106.107~16.04.1
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1019.24, 4.4.0-1010.13, 4.4.0-1011.14
Ubuntu:20.04:LTSlinux-raspi5.4.0-1015.15, 5.4.0-1013.13, 5.4.0-1012.12
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-fips0, 4.15.0-1027.32, 4.15.0-1038.43
Ubuntu:18.04:LTSlinux-aws4.15.0-1003.3, 4.15.0-1005.5, 0
Ubuntu:16.04:LTSlinux-aws4.4.0-1090.101, 4.4.0-1092.103, 4.4.0-1094.105
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-aws-fips0, 5.4.0-1021.21+fips2
Ubuntu:18.04:LTSlinux-gcp5.0.0-1034.35, 5.0.0-1033.34, 5.0.0-1031.32
Ubuntu:16.04:LTSlinux-gcp4.13.0-1011.15, 0, 4.10.0-1004.4

…and 50 more

Timeline

References

Open in Interactive Console →