CVE Vulnerabilities

CVE-2020-10027

Incorrect Comparison

Published: May 11, 2020 | Modified: Jun 05, 2020
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.

Weakness

The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Zephyr Zephyrproject 1.14.0 (including) 1.14.0 (including)
Zephyr Zephyrproject 2.1.0 (including) 2.1.0 (including)

Extended Description

This Pillar covers several possibilities:

References