Zephyr是美国Linux基金会的一套开源的小型的可缩放的实时操作系统。 Zephyr 1.14.0及之后版本(1.14.2版本已修复)和2.1.0及之后版本(2.2.0版本已修复)中的GPIO子系统存在输入验证错误漏洞,该漏洞源于在进行多个系统调用时,程序没有执行参数验证。攻击者可借助特制请求利用该漏洞执行任意代码以获取提升的权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject-rtos | zephyr | 1.14.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-10022 | 9.0 CRITICAL | UpdateHub Module Copies a Variable-Size Hash String Into a Fixed-Size Array |
| CVE-2020-10019 | 8.1 HIGH | Buffer Overflow in USB DFU requested length |
| CVE-2020-10021 | 8.1 HIGH | Out-of-bounds write in USB Mass Storage with unaligned sizes |
| CVE-2020-10060 | 8.0 HIGH | UpdateHub Might Dereference An Uninitialized Pointer |
| CVE-2020-10024 | 7.8 HIGH | ARM Platform Uses Signed Integer Comparison When Validating Syscall Numbers |
| CVE-2020-10027 | 7.8 HIGH | ARC Platform Uses Signed Integer Comparison When Validating Syscall Numbers |
| CVE-2020-10058 | 7.8 HIGH | Multiple Syscalls In kscan Subsystem Performs No Argument Validation |
| CVE-2020-10067 | 7.5 HIGH | Integer Overflow In is_in_region Allows User Thread To Access Kernel Memory |
| CVE-2020-10023 | 6.9 MEDIUM | Shell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trim |
| CVE-2020-10059 | 4.8 MEDIUM | UpdateHub Module Explicitly Disables TLS Verification |
No comments yet