CVE-2020-28588 is an information disclosure vulnerability in the Linux Kernel, specifically affecting versions 5.1 Stable through 5.10-rc4. An attacker can exploit this by reading /proc/pid/syscall, causing the kernel to leak memory contents. With a CVSS score of 5.5 (Medium), this vulnerability requires local access and low privileges, but can lead to high confidentiality impact by disclosing sensitive memory data. There is no integrity or availability impact. Currently, there is no known active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. While it has garnered some community discussion and media coverage, it is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.4.66CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.4.66:*:*:*:*:*:*:* | ||
5.9.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.9.8:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.10:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.