Medium severity4.4NVD Advisory· Published Apr 17, 2020· Updated Jun 17, 2026
CVE-2020-0067
CVE-2020-0067
Description
In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: Android. Versions: Android kernel. Android ID: A-120551147.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- Android/Android kerneldescription
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
Patches
Vulnerability mechanics
References
8- android.googlesource.com/kernel/common/+/688078e7nvdVendor Advisory
- packetstormsecurity.com/files/159565/Kernel-Live-Patch-Security-Notice-LSN-0072-1.htmlnvdThird Party AdvisoryVDB Entry
- source.android.com/security/bulletin/pixel/2020-04-01nvdVendor Advisory
- usn.ubuntu.com/4387-1/nvdThird Party Advisory
- usn.ubuntu.com/4388-1/nvdThird Party Advisory
- usn.ubuntu.com/4389-1/nvdThird Party Advisory
- usn.ubuntu.com/4390-1/nvdThird Party Advisory
- usn.ubuntu.com/4527-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.