CVE-2020-12653

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.

References

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b70261a288ea4d2f4ac7cd04be08a9f0f2de4f4d

https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.4

https://github.com/torvalds/linux/commit/b70261a288ea4d2f4ac7cd04be08a9f0f2de4f4d

http://www.openwall.com/lists/oss-security/2020/05/08/2

https://security.netapp.com/advisory/ntap-20200608-0001/

https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html

https://www.debian.org/security/2020/dsa-4698

http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html

Details

Source: MITRE

Published: 2020-05-05

Updated: 2021-07-21

Type: CWE-269

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Tenable Plugins

View all (43 total)

IDNameProductFamilySeverity
150553SUSE SLES11 Security Update : kernel (SUSE-SU-2020:14393-1)NessusSuSE Local Security Checks
high
147273NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2021-0008)NessusNewStart CGSL Local Security Checks
medium
146248OracleVM 3.4 : Unbreakable / etc (OVMSA-2021-0005)NessusOracleVM Local Security Checks
medium
146096Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9030)NessusOracle Linux Local Security Checks
medium
140917EulerOS 2.0 SP3 : kernel (EulerOS-SA-2020-2150)NessusHuawei Local Security Checks
medium
140378SUSE SLES15 Security Update : kernel (SUSE-SU-2020:2487-1)NessusSuSE Local Security Checks
medium
140328EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1958)NessusHuawei Local Security Checks
high
139620RHEL 6 : kernel-rt (RHSA-2020:3389)NessusRed Hat Local Security Checks
high
139537RHEL 7 : kernel (RHSA-2020:3432)NessusRed Hat Local Security Checks
high
139332RHEL 7 : kernel (RHSA-2020:3232)NessusRed Hat Local Security Checks
high
139235CentOS 7 : kernel (CESA-2020:3220)NessusCentOS Local Security Checks
medium
139219Oracle Linux 7 : kernel (ELSA-2020-3220) (deprecated)NessusOracle Linux Local Security Checks
medium
139200RHEL 7 : kernel-rt (RHSA-2020:3221)NessusRed Hat Local Security Checks
medium
139199RHEL 7 : kernel (RHSA-2020:3220)NessusRed Hat Local Security Checks
medium
139197RHEL 7 : kernel (RHSA-2020:3226)NessusRed Hat Local Security Checks
high
139195RHEL 7 : kernel (RHSA-2020:3224)NessusRed Hat Local Security Checks
high
139187RHEL 8 : kernel (RHSA-2020:3222)NessusRed Hat Local Security Checks
medium
138807RHEL 8 : kernel-rt (RHSA-2020:3016)NessusRed Hat Local Security Checks
high
138805RHEL 8 : kernel (RHSA-2020:3010)NessusRed Hat Local Security Checks
high
138798RHEL 8 : kernel (RHSA-2020:3041)NessusRed Hat Local Security Checks
high
138679openSUSE Security Update : the Linux Kernel (openSUSE-2020-801)NessusSuSE Local Security Checks
medium
138418Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5755)NessusOracle Linux Local Security Checks
high
138304SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1779-1)NessusSuSE Local Security Checks
high
138272SUSE SLES15 Security Update : kernel (SUSE-SU-2020:1663-1)NessusSuSE Local Security Checks
critical
138157RHEL 7 : kernel (RHSA-2020:2832)NessusRed Hat Local Security Checks
high
137932EulerOS Virtualization 3.0.6.0 : kernel (EulerOS-SA-2020-1713)NessusHuawei Local Security Checks
medium
137805EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-1698)NessusHuawei Local Security Checks
medium
137617SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1605-1)NessusSuSE Local Security Checks
medium
137616SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1603-1)NessusSuSE Local Security Checks
medium
137615SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1602-1)NessusSuSE Local Security Checks
medium
137613SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:1599-1)NessusSuSE Local Security Checks
medium
137612SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1597-1)NessusSuSE Local Security Checks
high
137611SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1596-1)NessusSuSE Local Security Checks
high
137608SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1587-1)NessusSuSE Local Security Checks
medium
137547SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1486-1)NessusSuSE Local Security Checks
high
137546SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1475-1)NessusSuSE Local Security Checks
high
137516EulerOS 2.0 SP2 : kernel (EulerOS-SA-2020-1674)NessusHuawei Local Security Checks
critical
137340Debian DSA-4698-1 : linux - security updateNessusDebian Local Security Checks
medium
137339Debian DLA-2242-1 : linux-4.9 security updateNessusDebian Local Security Checks
medium
137290Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2020-5714)NessusOracle Linux Local Security Checks
medium
137283Debian DLA-2241-2 : linux security updateNessusDebian Local Security Checks
medium
137024EulerOS 2.0 SP5 : kernel (EulerOS-SA-2020-1606)NessusHuawei Local Security Checks
medium
136870EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1592)NessusHuawei Local Security Checks
high