PT-2020-3138 · Linux+6 · Linux Kernel+6

Published

2020-04-27

·

Updated

2023-02-12

·

CVE-2020-10751

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.7
Description A flaw in the Linux kernel's SELinux LSM hook implementation allows for insufficient authentication of data. This issue arises because the hook incorrectly assumes that a socket buffer (skb) contains only a single netlink message and validates only the first message, potentially granting unauthorized access to subsequent messages within the skb. The vulnerability may enable an attacker to gain unauthorized access to protected information.
Recommendations For Linux kernel versions prior to 5.7, update to version 5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to SELinux LSM hook implementation until a patch is available.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4431
BDU:2020-03430
CESA-2020_4060
CESA-2020_4431
CESA-2020_4609
CVE-2020-10751
DLA-2241-1
DLA-2241-2
DLA-2242-1
DSA-4698-1
DSA-4699-1
OPENSUSE-SU-2020:0801-1
OPENSUSE-SU-2020:0935-1
OPENSUSE-SU-2020_0801-1
OPENSUSE-SU-2020_0935-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
RHSA-2020:4060
RHSA-2020:4062
RHSA-2020:4431
RHSA-2020:4609
RHSA-2020_4060
RHSA-2020_4062
RHSA-2020_4431
RHSA-2020_4609
SUSE-SU-2020:1587-1
SUSE-SU-2020:1599-1
SUSE-SU-2020:1602-1
SUSE-SU-2020:1603-1
SUSE-SU-2020:1604-1
SUSE-SU-2020:1605-1
SUSE-SU-2020:1663-1
SUSE-SU-2020:2027-1
SUSE-SU-2020:2105-1
SUSE-SU-2020:2134-1
SUSE-SU-2020:2152-1
SUSE-SU-2020:2156-1
SUSE-SU-2020:2478-1
SUSE-SU-2020:2487-1
SUSE-SU-2020_1587-1
SUSE-SU-2020_1599-1
SUSE-SU-2020_1602-1
SUSE-SU-2020_1603-1
SUSE-SU-2020_1604-1
SUSE-SU-2020_1605-1
SUSE-SU-2020_1663-1
USN-4389-1
USN-4390-1
USN-4391-1
USN-4412-1
USN-4413-1

Affected Products

Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu