5.9
CVE-2020-10711
- EPSS 3.1%
- Veröffentlicht 22.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:54
- Erkennungen
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 5.7
Redhat ≫ Virtualization Host Version 4.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Aus Version 7.4
Redhat ≫ Enterprise Linux Server Tus Version 7.4
Redhat ≫ Messaging Realtime Grid Version 2.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.1% | 0.86 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
| RedHat | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html
https://security.netapp.com/advisory/ntap-20200608-0001/
https://usn.ubuntu.com/4414-1/
https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
https://www.debian.org/security/2020/dsa-4698
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html
https://www.debian.org/security/2020/dsa-4699
https://usn.ubuntu.com/4419-1/
https://usn.ubuntu.com/4411-1/
https://usn.ubuntu.com/4412-1/
https://usn.ubuntu.com/4413-1/
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10711
https://www.openwall.com/lists/oss-security/2020/05/12/2