A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KDFONTOP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.
[
{
"target": {
"file": "drivers/tty/vt/vt.c"
},
"id": "CVE-2020-28974-c70c330e",
"deprecated": false,
"digest": {
"line_hashes": [
"59371693663903332835445616130219996662",
"124507623985814977843814325296805929958",
"130233172387298269491719387263294050574",
"322114892536121575181715254831769417846",
"64114270291726919620419662959955422229",
"316573903005917116000553964623265300288",
"45287133486760742212449636321928735486",
"263499669750966286584081159421983011210",
"330285379023677620298839700074933834945",
"272094011510204665798755435415111550806",
"271257119671679865174492606650613985521",
"305513828125401789033252816545850945630",
"262684704284043377408021397717794815144",
"119842287089041563535414526863388193526",
"299017857814465514475274500459674493113",
"84041554207295520360030902366711014571",
"128269922702212872524347338730010934710",
"240503431468936828861931375676847574583",
"244016029646028344271789656523952358143",
"58303115345760382093666293304262455712",
"157403288878895601992145728143825596765",
"44006337601804902909060032924349156525",
"295683419781355628553980759064883595704",
"42841700294403231711722139228709780829",
"260194362725424525598756567808149819237"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3c4e0dff2095c579b142d5a0693257f1c58b4804",
"signature_version": "v1"
},
{
"target": {
"function": "con_font_op",
"file": "drivers/tty/vt/vt.c"
},
"id": "CVE-2020-28974-e5d97b1d",
"deprecated": false,
"digest": {
"length": 341.0,
"function_hash": "70032905855337286752275237941938225323"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3c4e0dff2095c579b142d5a0693257f1c58b4804",
"signature_version": "v1"
},
{
"target": {
"function": "con_font_copy",
"file": "drivers/tty/vt/vt.c"
},
"id": "CVE-2020-28974-ec32a2e6",
"deprecated": false,
"digest": {
"length": 414.0,
"function_hash": "339209042671430974947651312044951127270"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@3c4e0dff2095c579b142d5a0693257f1c58b4804",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28974.json"