PT-2020-5328 · Linux+8 · Linux Kernel+8

Chennan

·

Published

2020-09-25

·

Updated

2023-05-16

·

CVE-2020-25643

CVSS v2.0

7.5

High

VectorAV:N/AC:M/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.9-rc7
Description A flaw in the HDLC PPP module of the Linux kernel causes memory corruption and a read overflow due to improper input validation in the ppp cp parse cr function. This can lead to a system crash or denial of service, posing a threat to data confidentiality, integrity, and system availability. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.9-rc7, update to version 5.9-rc7 or later to resolve the issue. As a temporary workaround, consider restricting access to the HDLC PPP module to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1578
ALT-PU-2020-2885
ALT-PU-2020-2886
ALT-PU-2020-2888
ALT-PU-2020-2935
ALT-PU-2020-2936
ALT-PU-2020-2937
ALT-PU-2020-3210
ALT-PU-2020-3454
ALT-PU-2020-3553
ALT-PU-2021-1083
ALT-PU-2021-1093
ALT-PU-2021-1105
ALT-PU-2021-1128
ALT-PU-2021-1531
ALT-PU-2021-1840
BDU:2021-00106
CESA-2020_5437
CESA-2021_1578
CESA-2021_1739
CVE-2020-25643
DLA-2417-1
DLA-2420-1
DLA-2420-2
DSA-4774-1
MGASA-2020-0392
OPENSUSE-SU-2020:1655-1
OPENSUSE-SU-2020:1698-1
OPENSUSE-SU-2020:2112-1
OPENSUSE-SU-2020_1655-1
OPENSUSE-SU-2020_1698-1
OPENSUSE-SU-2020_2112-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
RHSA-2020:5437
RHSA-2020:5441
RHSA-2020_5437
RHSA-2020_5441
RHSA-2021:1578
RHSA-2021:1739
RHSA-2021_1578
RHSA-2021_1739
SUSE-SU-2020:2904-1
SUSE-SU-2020:2905-1
SUSE-SU-2020:2906-1
SUSE-SU-2020:2907-1
SUSE-SU-2020:2980-1
SUSE-SU-2020:2999-1
SUSE-SU-2020:3014-1
SUSE-SU-2020:3230-1
SUSE-SU-2020:3491-1
SUSE-SU-2020:3501-1
SUSE-SU-2020:3503-1
SUSE-SU-2020:3532-1
SUSE-SU-2020:3544-1
SUSE-SU-2021:14630-1
SUSE-SU-2021_14630-1
USN-4657-1
USN-4658-1
USN-4658-2
USN-4660-1
USN-4660-2
USN-4752-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu