7.5

CVE-2020-25643

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 2.6.29 < 4.4.238
LinuxLinux Kernel Version >= 4.5 < 4.9.238
LinuxLinux Kernel Version >= 4.10 < 4.14.200
LinuxLinux Kernel Version >= 4.15 < 4.19.148
LinuxLinux Kernel Version >= 4.20 < 5.4.68
LinuxLinux Kernel Version >= 5.5 < 5.8.12
LinuxLinux Kernel Version5.9.0 Updaterc1
LinuxLinux Kernel Version5.9.0 Updaterc2
LinuxLinux Kernel Version5.9.0 Updaterc3
LinuxLinux Kernel Version5.9.0 Updaterc4
LinuxLinux Kernel Version5.9.0 Updaterc5
LinuxLinux Kernel Version5.9.0 Updaterc6
RedhatEnterprise Linux Version7.0
RedhatEnterprise Linux Version8.0
OpensuseLeap Version15.1
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
OpensuseLeap Version15.2
NetappH410c Firmware Version-
   NetappH410c Version-
StarwindsoftwareStarwind Virtual San Versionv8 Updatebuild12533 SwPlatformvsphere
StarwindsoftwareStarwind Virtual San Versionv8 Updatebuild12658 SwPlatformvsphere
StarwindsoftwareStarwind Virtual San Versionv8 Updatebuild12859 SwPlatformvsphere
StarwindsoftwareStarwind Virtual San Versionv8 Updatebuild13170 SwPlatformvsphere
StarwindsoftwareStarwind Virtual San Versionv8 Updatebuild13586 SwPlatformvsphere
StarwindsoftwareStarwind Virtual San Versionv8 Updatebuild13861 SwPlatformvsphere
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.596
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 6.8 8.5
AV:N/AC:M/Au:S/C:P/I:P/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.