CVE-2020-25212

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

References

https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.3

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b4487b93545214a9db8cbf32e86411677b0cca21

https://twitter.com/grsecurity/status/1303370421958578179

https://usn.ubuntu.com/4527-1/

https://usn.ubuntu.com/4525-1/

https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html

https://usn.ubuntu.com/4578-1/

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00035.html

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html

https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html

https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html

Details

Source: MITRE

Published: 2020-09-09

Updated: 2021-07-21

Type: CWE-367

Risk Information

CVSS v2

Base Score: 4.4

Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Tenable Plugins

View all (59 total)

IDNameProductFamilySeverity
149914Oracle Linux 8 : kernel (ELSA-2021-1578)NessusOracle Linux Local Security Checks
high
149874CentOS 8 : kernel (CESA-2021:1578)NessusCentOS Local Security Checks
high
149670RHEL 8 : kernel (RHSA-2021:1578)NessusRed Hat Local Security Checks
high
149660RHEL 8 : kernel-rt (RHSA-2021:1739)NessusRed Hat Local Security Checks
high
147982Ubuntu 20.04 LTS : Linux kernel (OEM) vulnerabilities (USN-4752-1)NessusUbuntu Local Security Checks
high
147842RHEL 7 : kernel (RHSA-2021:0878)NessusRed Hat Local Security Checks
high
147690EulerOS Virtualization 2.9.0 : kernel (EulerOS-SA-2021-1642)NessusHuawei Local Security Checks
high
147512EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-1604)NessusHuawei Local Security Checks
high
147345NewStart CGSL MAIN 6.02 : kernel Multiple Vulnerabilities (NS-SA-2021-0051)NessusNewStart CGSL Local Security Checks
high
147338NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2021-0012)NessusNewStart CGSL Local Security Checks
high
147209RHEL 7 : kernel (RHSA-2021:0760)NessusRed Hat Local Security Checks
high
146532RHEL 7 : kernel (RHSA-2021:0526)NessusRed Hat Local Security Checks
high
146282openSUSE Security Update : RT kernel (openSUSE-2021-242)NessusSuSE Local Security Checks
high
145201EulerOS 2.0 SP3 : kernel (EulerOS-SA-2021-1079)NessusHuawei Local Security Checks
high
144831EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056)NessusHuawei Local Security Checks
critical
144731EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2021-1039)NessusHuawei Local Security Checks
high
144549CentOS 7 : kernel (CESA-2020:5437)NessusCentOS Local Security Checks
high
144404RHEL 7 : kernel (RHSA-2020:5437)NessusRed Hat Local Security Checks
high
144402RHEL 7 : kernel-rt (RHSA-2020:5441)NessusRed Hat Local Security Checks
high
144333Oracle Linux 7 : kernel (ELSA-2020-5437)NessusOracle Linux Local Security Checks
high
144295Scientific Linux Security Update : kernel on SL7.x x86_64 (2020:5437)NessusScientific Linux Local Security Checks
high
143875SUSE SLES15 Security Update : kernel (SUSE-SU-2020:3532-1)NessusSuSE Local Security Checks
high
143857SUSE SLES12 Security Update : kernel (SUSE-SU-2020:3544-1)NessusSuSE Local Security Checks
high
143844SUSE SLES12 Security Update : kernel (SUSE-SU-2020:3225-1)NessusSuSE Local Security Checks
high
143801SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:2905-1)NessusSuSE Local Security Checks
high
143784SUSE SLES15 Security Update : kernel (SUSE-SU-2020:3014-1)NessusSuSE Local Security Checks
high
143773SUSE SLES12 Security Update : kernel (SUSE-SU-2020:3281-1)NessusSuSE Local Security Checks
high
143772SUSE SLES12 Security Update : kernel (SUSE-SU-2020:3219-1)NessusSuSE Local Security Checks
high
143708SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2904-1)NessusSuSE Local Security Checks
high
143699SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2907-1)NessusSuSE Local Security Checks
high
143694SUSE SLES15 Security Update : kernel (SUSE-SU-2020:3230-1)NessusSuSE Local Security Checks
high
143673SUSE SLES12 Security Update : kernel (SUSE-SU-2020:2981-1)NessusSuSE Local Security Checks
high
143654SUSE SLES12 Security Update : kernel (SUSE-SU-2020:3501-1)NessusSuSE Local Security Checks
high
143639SUSE SLES12 Security Update : kernel (SUSE-SU-2020:3503-1)NessusSuSE Local Security Checks
high
143398openSUSE Security Update : the Linux Kernel (openSUSE-2020-2112)NessusSuSE Local Security Checks
high
142240EulerOS 2.0 SP2 : kernel (EulerOS-SA-2020-2353)NessusHuawei Local Security Checks
high
142176Debian DLA-2420-2 : linux regression updateNessusDebian Local Security Checks
high
142112EulerOS 2.0 SP5 : kernel (EulerOS-SA-2020-2303)NessusHuawei Local Security Checks
medium
141961Amazon Linux AMI : kernel (ALAS-2020-1437)NessusAmazon Linux Local Security Checks
high
141789Slackware 14.2 : Slackware 14.2 kernel (SSA:2020-295-01)NessusSlackware Local Security Checks
high
141559openSUSE Security Update : the Linux Kernel (openSUSE-2020-1698)NessusSuSE Local Security Checks
high
141546RHEL 7 : kernel-alt (RHSA-2020:4279)NessusRed Hat Local Security Checks
high
141514openSUSE Security Update : the Linux Kernel (openSUSE-2020-1682)NessusSuSE Local Security Checks
high
141448Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4578-1)NessusUbuntu Local Security Checks
high
141445Photon OS 2.0: Linux PHSA-2020-2.0-0288NessusPhotonOS Local Security Checks
high
141396Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5885)NessusOracle Linux Local Security Checks
high
141395Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2020-5884)NessusOracle Linux Local Security Checks
high
141388openSUSE Security Update : the Linux Kernel (openSUSE-2020-1655)NessusSuSE Local Security Checks
high
141374OracleVM 3.4 : Unbreakable / etc (OVMSA-2020-0044)NessusOracleVM Local Security Checks
critical
141332EulerOS 2.0 SP9 : kernel (EulerOS-SA-2020-2166)NessusHuawei Local Security Checks
high
141329EulerOS 2.0 SP9 : kernel (EulerOS-SA-2020-2176)NessusHuawei Local Security Checks
high
141207Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2020-5866)NessusOracle Linux Local Security Checks
critical
141106Amazon Linux 2 : kernel (ALAS-2020-1495)NessusAmazon Linux Local Security Checks
medium
140999EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-2151)NessusHuawei Local Security Checks
high
140959EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-2011)NessusHuawei Local Security Checks
medium
140933Debian DLA-2385-1 : linux-4.19 security updateNessusDebian Local Security Checks
high
140724Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4527-1)NessusUbuntu Local Security Checks
high
140723Ubuntu 20.04 LTS : Linux kernel vulnerabilities (USN-4525-1)NessusUbuntu Local Security Checks
high
140708Photon OS 3.0: Linux PHSA-2020-3.0-0142NessusPhotonOS Local Security Checks
high