---
id: CVE-2020-14304
title: >-
  A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in
  the way it read data from the EEPROM of the device
summary: >-
  A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in
  the way it read data from the EEPROM of the device. This flaw allows a local
  user to read uninitialized values from the kernel memory. The highest threat
  from …
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-460
  - CWE-755
vendor: linux
product: linux_kernel
affected:
  - linux_kernel = 4.9.210-1
  - linux_kernel = 4.19.118-2
  - linux_kernel = 5.6.7-1
published: '2020-09-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:16.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-14304'
references:
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960702'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14304'
    label: secalert@redhat.com
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960702'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14304'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T18:53:27.845189Z'
epss: 0.00382
epssPercentile: 0.30044
ingestedAt: '2026-10-07T19:44:15.638Z'
---

## Overview

A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.

## Affected

- `linux_kernel = 4.9.210-1`
- `linux_kernel = 4.19.118-2`
- `linux_kernel = 5.6.7-1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
