CVE-2020-11494: Canonical Ubuntu Linux

Medium severity, CVSS 4.4. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Linux Linux Kernel: from 3.16, up to and including 5.6.2
  • Opensuse Leap: version 15.1 only

Published 2020-04-02. Last modified 2026-10-08.