5.9

CVE-2020-10711

A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.7
Redhat ≫ 3scale Version 2.0
Redhat ≫ Openstack Version 13
Redhat ≫ Virtualization Host Version 4.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Aus Version 7.4
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.1% 0.86
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20200608-0001/
Third Party Advisory
https://usn.ubuntu.com/4414-1/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
Third Party Advisory
https://www.debian.org/security/2020/dsa-4698
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2020/dsa-4699
Third Party Advisory
https://usn.ubuntu.com/4419-1/
Third Party Advisory
https://usn.ubuntu.com/4411-1/
Third Party Advisory
https://usn.ubuntu.com/4412-1/
Third Party Advisory
https://usn.ubuntu.com/4413-1/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10711
Patch
Third Party Advisory
Issue Tracking
https://www.openwall.com/lists/oss-security/2020/05/12/2
Patch
Third Party Advisory
Mailing List