CVE-2020-36158

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.

References

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5c455c5ab332773464d02ba17015acdca198f03d

https://github.com/torvalds/linux/commit/5c455c5ab332773464d02ba17015acdca198f03d

https://lists.debian.org/debian-lts-announce/2021/02/msg00018.html

https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/HCHBIRS27VMOGMBHPWP2R7SZRFXT6O6U/

https://lore.kernel.org/r/[email protected]

https://patchwork.kernel.org/project/linux-wireless/patch/[email protected]/

https://security.netapp.com/advisory/ntap-20210212-0002/

https://www.debian.org/security/2021/dsa-4843

Details

Source: MITRE

Published: 2021-01-05

Updated: 2021-03-09

Type: CWE-120

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 6.7

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 0.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 5.10.4 (inclusive)

Configuration 2

OR

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

Tenable Plugins

View all (44 total)

IDNameProductFamilySeverity
151229EulerOS Virtualization 3.0.6.6 : kernel (EulerOS-SA-2021-2040)NessusHuawei Local Security Checks
high
150536SUSE SLES11 Security Update : kernel (SUSE-SU-2021:14630-1)NessusSuSE Local Security Checks
high
149098EulerOS 2.0 SP3 : kernel (EulerOS-SA-2021-1808)NessusHuawei Local Security Checks
high
148634EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-1715)NessusHuawei Local Security Checks
high
148550Oracle Linux 7 / 8 : Unbreakable Enterprise kernel-container (ELSA-2021-9038)NessusOracle Linux Local Security Checks
medium
148549Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2021-9037)NessusOracle Linux Local Security Checks
medium
148494Ubuntu 20.04 LTS : Linux kernel (OEM) vulnerabilities (USN-4912-1)NessusUbuntu Local Security Checks
high
148041EulerOS 2.0 SP5 : kernel (EulerOS-SA-2021-1684)NessusHuawei Local Security Checks
high
148003Ubuntu 18.04 LTS / 20.04 LTS : Linux kernel vulnerabilities (USN-4878-1)NessusUbuntu Local Security Checks
high
148001Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4876-1)NessusUbuntu Local Security Checks
medium
147992Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4877-1)NessusUbuntu Local Security Checks
medium
147974Ubuntu 20.04 LTS / 20.10 : Linux kernel vulnerabilities (USN-4879-1)NessusUbuntu Local Security Checks
medium
147588EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2021-1386)NessusHuawei Local Security Checks
high
147532Debian DLA-2586-1 : linux security updateNessusDebian Local Security Checks
high
146701EulerOS 2.0 SP2 : kernel (EulerOS-SA-2021-1311)NessusHuawei Local Security Checks
high
146512Debian DLA-2557-1 : linux-4.19 security updateNessusDebian Local Security Checks
high
146511SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0452-1)NessusSuSE Local Security Checks
high
146476SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0437-1)NessusSuSE Local Security Checks
high
146474SUSE SLES15 Security Update : kernel (SUSE-SU-2021:0438-1)NessusSuSE Local Security Checks
high
146470SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0434-1)NessusSuSE Local Security Checks
high
146401SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0408-1)NessusSuSE Local Security Checks
medium
146362SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0348-1)NessusSuSE Local Security Checks
high
146352Oracle Linux 6 : Unbreakable Enterprise kernel (ELSA-2021-9043)NessusOracle Linux Local Security Checks
medium
146305Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9041) (deprecated)NessusOracle Linux Local Security Checks
medium
146304Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9040)NessusOracle Linux Local Security Checks
medium
146300Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2021-9035)NessusOracle Linux Local Security Checks
medium
146299Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9039)NessusOracle Linux Local Security Checks
medium
146282openSUSE Security Update : RT kernel (openSUSE-2021-242)NessusSuSE Local Security Checks
high
146261EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-1265)NessusHuawei Local Security Checks
medium
146248OracleVM 3.4 : Unbreakable / etc (OVMSA-2021-0005)NessusOracleVM Local Security Checks
medium
146217EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-1246)NessusHuawei Local Security Checks
medium
146096Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9030)NessusOracle Linux Local Security Checks
medium
146052Debian DSA-4843-1 : linux - security updateNessusDebian Local Security Checks
high
145726EulerOS 2.0 SP8 : kernel (EulerOS-SA-2021-1148)NessusHuawei Local Security Checks
medium
145459Photon OS 2.0: Linux PHSA-2021-2.0-0314NessusPhotonOS Local Security Checks
medium
145320openSUSE Security Update : the Linux Kernel (openSUSE-2021-60)NessusSuSE Local Security Checks
medium
145287openSUSE Security Update : the Linux Kernel (openSUSE-2021-75)NessusSuSE Local Security Checks
medium
145231Photon OS 1.0: Linux PHSA-2021-1.0-0354NessusPhotonOS Local Security Checks
medium
145120SUSE SLES12 Security Update : kernel (SUSE-SU-2021:0133-1)NessusSuSE Local Security Checks
medium
145025SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:0117-1)NessusSuSE Local Security Checks
medium
145018SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:0118-1)NessusSuSE Local Security Checks
medium
144966Fedora 33 : kernel / kernel-headers (2021-3465ada1ca)NessusFedora Local Security Checks
medium
144959SUSE SLES15 Security Update : kernel (SUSE-SU-2021:0108-1)NessusSuSE Local Security Checks
medium
144908SUSE SLES15 Security Update : kernel (SUSE-SU-2021:0095-1)NessusSuSE Local Security Checks
medium