CVE-2020-25670

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.

References

https://lists.fedoraproject.org/archives/list/[email protected]/message/PW3OASG7OEMHANDWBM5US5WKTOC76KMH/

http://www.openwall.com/lists/oss-security/2020/11/01/1

https://lists.fedoraproject.org/archives/list/[email protected]/message/UTVACC6PGS6OSD3EYY7FZUAZT2EUMFH5/

http://www.openwall.com/lists/oss-security/2021/05/11/4

https://www.openwall.com/lists/oss-security/2020/11/01/1

https://lists.fedoraproject.org/archives/list/[email protected]/message/VEIEGQXUW37YHZ5MTAZTDCIMHUN26NJS/

https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html

https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html

Details

Source: MITRE

Published: 2021-05-26

Updated: 2021-07-02

Type: CWE-416

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (38 total)

IDNameProductFamilySeverity
154404EulerOS 2.0 SP3 : kernel (EulerOS-SA-2021-2588)NessusHuawei Local Security Checks
high
153271EulerOS 2.0 SP2 : kernel (EulerOS-SA-2021-2392)NessusHuawei Local Security Checks
high
153080EulerOS 2.0 SP5 : kernel (EulerOS-SA-2021-2336)NessusHuawei Local Security Checks
high
152465Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9410)NessusOracle Linux Local Security Checks
high
152464Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2021-9407)NessusOracle Linux Local Security Checks
high
152313EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-2272)NessusHuawei Local Security Checks
high
152308EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-2246)NessusHuawei Local Security Checks
high
151897Slackware 14.2 : Slackware 14.2 kernel (SSA:2021-202-01)NessusSlackware Local Security Checks
high
151756openSUSE 15 Security Update : kernel (openSUSE-SU-2021:1977-1)NessusSuSE Local Security Checks
critical
151730openSUSE 15 Security Update : kernel (openSUSE-SU-2021:1975-1)NessusSuSE Local Security Checks
critical
151690Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2021-9362)NessusOracle Linux Local Security Checks
high
151689Oracle Linux 7 / 8 : Unbreakable Enterprise kernel-container (ELSA-2021-9363)NessusOracle Linux Local Security Checks
high
151570EulerOS Virtualization 2.9.0 : kernel (EulerOS-SA-2021-2195)NessusHuawei Local Security Checks
high
151562EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-2183)NessusHuawei Local Security Checks
high
150985Debian DLA-2689-1 : linux security updateNessusDebian Local Security Checks
high
150984Debian DLA-2690-1 : linux-4.19 security updateNessusDebian Local Security Checks
high
150954Ubuntu 20.04 LTS / 20.10 : Linux kernel vulnerabilities (USN-4999-1)NessusUbuntu Local Security Checks
high
150927SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1975-1)NessusSuSE Local Security Checks
critical
150901SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:1977-1)NessusSuSE Local Security Checks
critical
150233Ubuntu 18.04 LTS / 20.04 LTS : Linux kernel vulnerabilities (USN-4982-1)NessusUbuntu Local Security Checks
medium
150155Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4979-1)NessusUbuntu Local Security Checks
medium
150151Ubuntu 21.04 : Linux kernel vulnerabilities (USN-4977-1)NessusUbuntu Local Security Checks
high
149892openSUSE Security Update : the Linux Kernel (openSUSE-2021-758)NessusSuSE Local Security Checks
critical
149872Amazon Linux AMI : kernel (ALAS-2021-1503)NessusAmazon Linux Local Security Checks
high
149717SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1624-1)NessusSuSE Local Security Checks
high
149716SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1623-1)NessusSuSE Local Security Checks
high
149633SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1617-1)NessusSuSE Local Security Checks
high
149605openSUSE Security Update : the Linux Kernel (openSUSE-2021-579)NessusSuSE Local Security Checks
high
149491SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1596-1)NessusSuSE Local Security Checks
high
149462SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1573-1)NessusSuSE Local Security Checks
high
149407Ubuntu 20.04 LTS : Linux kernel (OEM) vulnerabilities (USN-4948-1)NessusUbuntu Local Security Checks
high
148919Amazon Linux 2 : kernel (ALAS-2021-1627)NessusAmazon Linux Local Security Checks
high
148753SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1248-1)NessusSuSE Local Security Checks
high
148747SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:1238-1)NessusSuSE Local Security Checks
critical
148732Fedora 33 : kernel / kernel-headers / kernel-tools (2021-1c170a7c7c)NessusFedora Local Security Checks
critical
148715Fedora 32 : kernel / kernel-headers / kernel-tools (2021-21360476b6)NessusFedora Local Security Checks
critical
148700SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1210-1)NessusSuSE Local Security Checks
high
148698SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1211-1)NessusSuSE Local Security Checks
critical