{"id":"CVE-2020-28097","details":"The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.","modified":"2026-04-11T12:34:15.384172Z","published":"2021-06-24T12:15:07.780Z","related":["SUSE-SU-2022:0363-1","SUSE-SU-2022:0364-1","SUSE-SU-2022:0370-1","SUSE-SU-2022:0372-1","SUSE-SU-2022:0543-1","SUSE-SU-2022:0555-1","openSUSE-SU-2022:0363-1","openSUSE-SU-2022:0370-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_FIELD","cpe":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","extracted_events":[{"fixed":"5.8.10"}]},{"source":"DESCRIPTION","extracted_events":[{"fixed":"5.8.10"}]}]},"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210805-0001/"},{"type":"FIX","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.10"},{"type":"FIX","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=973c096f6a85e5b5f2a295126ba6928d9a6afd45"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/973c096f6a85e5b5f2a295126ba6928d9a6afd45"},{"type":"FIX","url":"https://seclists.org/oss-sec/2020/q3/176"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git","events":[{"introduced":"0"},{"fixed":"973c096f6a85e5b5f2a295126ba6928d9a6afd45"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28097.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/torvalds/linux","events":[{"introduced":"0"},{"fixed":"973c096f6a85e5b5f2a295126ba6928d9a6afd45"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28097.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}