PT-2020-2225 · Linux+7 · Linux Kernel+7
Bui Quang Minh
·
Published
2020-04-15
·
Updated
2024-02-01
·
CVE-2020-12659
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.6.7
Description
An issue in the Linux kernel allows for an out-of-bounds write due to a lack of headroom validation in
xdp umem reg in net/xdp/xdp umem.c. This can be exploited by a user with the CAP NET ADMIN capability. The issue may impact the confidentiality, integrity, and availability of protected information.Recommendations
For Linux kernel versions prior to 5.6.7, update to version 5.6.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
CAP NET ADMIN capability to minimize the risk of exploitation.Exploit
Fix
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu