Vulnerability Description
The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:serial8250_isa_init_ports() that allows local users to cause a denial of service by using the p->serial_in pointer which uninitialized.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.8 |
Related Weaknesses (CWE)
References
- https://lkml.org/lkml/2020/7/21/80ExploitPatchVendor Advisory
- https://lkml.org/lkml/2020/7/21/80ExploitPatchVendor Advisory
FAQ
What is CVE-2020-15437?
CVE-2020-15437 is a vulnerability with a CVSS score of 4.4 (MEDIUM). The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:serial8250_isa_init_ports() that allows local users to cause a denial of service ...
How severe is CVE-2020-15437?
CVE-2020-15437 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15437?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.