PT-2020-5266 · Linux+6 · Linux Kernel+6

Matthew Sheets

·

Published

2020-05-12

·

Updated

2022-04-22

·

CVE-2020-10711

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.7
Description A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the ebitmap netlbl import routine. The issue arises when processing the CIPSO restricted bitmap tag in the cipso v4 parsetag rbm routine, which sets the security attribute to indicate the presence of a category bitmap even if it has not been allocated. This leads to a NULL pointer dereference issue, allowing a remote network user to crash the system kernel and resulting in a denial of service.
Recommendations For Linux kernel versions prior to 5.7, update to version 5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the SELinux subsystem to minimize the risk of exploitation. Avoid using the ebitmap netlbl import routine and the cipso v4 parsetag rbm routine until the issue is resolved.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2098
ALT-PU-2020-2164
ALT-PU-2020-2209
ALT-PU-2020-2409
ALT-PU-2020-2432
ALT-PU-2020-2687
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2020-05900
BDU:2021-00445
CESA-2020_2102
CESA-2020_2103
CESA-2020_2125
CESA-2020_2171
CVE-2020-10711
DLA-2242-1
DSA-4698-1
DSA-4699-1
MGASA-2020-0227
MGASA-2020-0228
OPENSUSE-SU-2020:0801-1
OPENSUSE-SU-2020:0935-1
OPENSUSE-SU-2020_0801-1
OPENSUSE-SU-2020_0935-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
RHSA-2020:2082
RHSA-2020:2085
RHSA-2020:2102
RHSA-2020:2103
RHSA-2020:2104
RHSA-2020:2125
RHSA-2020:2171
RHSA-2020:2199
RHSA-2020:2203
RHSA-2020:2214
RHSA-2020:2242
RHSA-2020:2277
RHSA-2020:2285
RHSA-2020:2289
RHSA-2020:2291
RHSA-2020:2429
RHSA-2020:2519
RHSA-2020:2522
RHSA-2020_2082
RHSA-2020_2085
RHSA-2020_2102
RHSA-2020_2103
RHSA-2020_2171
SUSE-SU-2020:1587-1
SUSE-SU-2020:1599-1
SUSE-SU-2020:1602-1
SUSE-SU-2020:1603-1
SUSE-SU-2020:1604-1
SUSE-SU-2020:1605-1
SUSE-SU-2020:1663-1
SUSE-SU-2020:2027-1
SUSE-SU-2020:2105-1
SUSE-SU-2020:2134-1
SUSE-SU-2020:2152-1
SUSE-SU-2020:2156-1
SUSE-SU-2020:2478-1
SUSE-SU-2020:2487-1
SUSE-SU-2020_1587-1
SUSE-SU-2020_1599-1
SUSE-SU-2020_1602-1
SUSE-SU-2020_1603-1
SUSE-SU-2020_1604-1
SUSE-SU-2020_1605-1
SUSE-SU-2020_1663-1
USN-4411-1
USN-4412-1
USN-4413-1
USN-4414-1
USN-4419-1

Affected Products

Alt Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu