CVE-2020-3872: Medium severity Apple tvOS vulnerability
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
Other sources
Kernel. A memory initialization issue was addressed with improved memory handling.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 6.1.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade
iOS/iPadOS/tvOS/watchOS/macOS Kernelto a version that resolves this vulnerability.Fixed in 13.3.1 - Upgrade
Upgrade
macOS Catalina Kernelto a version that resolves this vulnerability.Fixed in 10.15.3 - Upgrade
Upgrade
watchOS Kernelto a version that resolves this vulnerability.Fixed in 6.1.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-3857
- CVE-2020-3855
- CVE-2020-3826
- CVE-2020-3870
- CVE-2020-3878
- CVE-2020-3880
- CVE-2020-3837
- CVE-2019-8836
- CVE-2020-3840
- CVE-2020-3875
- CVE-2020-3872
- CVE-2020-3836
- CVE-2020-3842
- CVE-2020-3853
- CVE-2020-3846
- CVE-2020-3856
- CVE-2020-3829
- CVE-2020-3825
- CVE-2020-3868
- CVE-2020-3862
- CVE-2020-3867
- CVE-2020-3865
- CVE-2020-3864
- CVE-2020-3838
- CVE-2020-3877
- CVE-2019-11043
- CVE-2020-3866
- CVE-2020-3848
- CVE-2020-3849
- CVE-2020-3850
- CVE-2020-3847
- CVE-2020-3835
- CVE-2020-3863
- CVE-2020-9774
- CVE-2020-3827
- CVE-2020-3845
- CVE-2020-3851
- CVE-2020-3871
- CVE-2020-3830
- CVE-2020-3854
- CVE-2019-18634
- CVE-2020-3839
- CVE-2020-3843
- CVE-2020-3834
- CVE-2020-3860
- CVE-2020-3869
- CVE-2020-3858
- CVE-2020-3831
- CVE-2020-3873
- CVE-2020-3859
- CVE-2020-3844
- CVE-2020-3828
- CVE-2020-3841
- CVE-2020-3874
Frequently Asked Questions
What is CVE-2020-3872?
CVE-2020-3872 is a vulnerability in the kernel that relates to a memory initialization issue.
How does CVE-2020-3872 affect Apple watchOS?
CVE-2020-3872 affects Apple watchOS versions up to, but not including, 6.1.2.
How does CVE-2020-3872 affect Apple tvOS?
CVE-2020-3872 affects Apple tvOS versions up to, but not including, 13.3.1.
How does CVE-2020-3872 affect Apple iOS?
CVE-2020-3872 affects Apple iOS versions up to, but not including, 13.3.1.
How does CVE-2020-3872 affect Apple iPadOS?
CVE-2020-3872 affects Apple iPadOS versions up to, but not including, 13.3.1.
How does CVE-2020-3872 affect Apple macOS Catalina?
CVE-2020-3872 affects Apple macOS Catalina versions up to, but not including, 10.15.3.
How does CVE-2020-3872 affect Apple Mojave?
The impact of CVE-2020-3872 on Apple Mojave is currently unknown.
How does CVE-2020-3872 affect Apple High Sierra?
The impact of CVE-2020-3872 on Apple High Sierra is currently unknown.
How can I fix CVE-2020-3872?
To fix CVE-2020-3872, you should update your Apple device to the latest version of watchOS, tvOS, iOS, iPadOS, or macOS Catalina, depending on the affected operating system.
Where can I find more information about CVE-2020-3872?
You can find more information about CVE-2020-3872 on the Apple support website.