CVE Vulnerabilities

CVE-2020-0306

Published: Sep 17, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480

Affected Software

Name Vendor Start Version End Version
Android Google 11.0 (including) 11.0 (including)
Llvm-toolchain-10 Ubuntu bionic *
Llvm-toolchain-10 Ubuntu groovy *
Llvm-toolchain-10 Ubuntu trusty *
Llvm-toolchain-11 Ubuntu groovy *
Llvm-toolchain-11 Ubuntu hirsute *
Llvm-toolchain-11 Ubuntu impish *
Llvm-toolchain-11 Ubuntu kinetic *
Llvm-toolchain-11 Ubuntu trusty *
Llvm-toolchain-8 Ubuntu bionic *
Llvm-toolchain-8 Ubuntu groovy *
Llvm-toolchain-8 Ubuntu trusty *
Llvm-toolchain-8 Ubuntu xenial *
Llvm-toolchain-9 Ubuntu bionic *
Llvm-toolchain-9 Ubuntu groovy *
Llvm-toolchain-9 Ubuntu hirsute *
Llvm-toolchain-9 Ubuntu impish *
Llvm-toolchain-9 Ubuntu trusty *

References