Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic
Published May 22, 2020
5.9
MEDIUMCVSS 3.1
EPSS 3.08%
Description
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.
Affected products
-
- Version all kernel versions before 5.7StatusaffectedConstraints-
- Version
Configuration 1
- < 5.7
Configuration 2
- 2.0
- 13
- 4.0
- 6.0
- 7.0
- 8.0
- 7.4
- 7.4
- 2.0
Configuration 3
- 8.0
- 9.0
- 10.0
Configuration 5
- 14.04
- 16.04
- 18.04
- 19.10
- 20.04
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.29.2.el6
Fixed · RHSA-2020:2103
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.8.2.el7
Fixed · RHSA-2020:2082
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.21.2.el7a
Fixed · RHSA-2020:2104
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1127.8.2.rt56.1103.el7
Fixed · RHSA-2020:2085
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.88.1.el7
Fixed · RHSA-2020:2285
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.76.1.el7
Fixed · RHSA-2020:2277
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.76.1.el7
Fixed · RHSA-2020:2277
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.76.1.el7
Fixed · RHSA-2020:2277
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.67.1.el7
Fixed · RHSA-2020:2214
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
kernel-0:3.10.0-693.67.1.el7
Fixed · RHSA-2020:2214
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
kernel-0:3.10.0-693.67.1.el7
Fixed · RHSA-2020:2214
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.54.1.el7
Fixed · RHSA-2020:2289
Red Hat Enterprise Linux 7.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2020:2291
Red Hat Enterprise Linux 7.7 Extended Update Support
kernel-0:3.10.0-1062.26.1.el7
Fixed · RHSA-2020:2522
Red Hat Enterprise Linux 7.7 Extended Update Support
kpatch-patch
Fixed · RHSA-2020:2519
Red Hat Enterprise Linux 8
kernel-0:4.18.0-193.1.2.el8_2
Fixed · RHSA-2020:2102
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-193.1.2.rt13.53.el8_2
Fixed · RHSA-2020:2171
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2020:2125
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
kernel-0:4.18.0-80.23.2.el8_0
Fixed · RHSA-2020:2429
Red Hat Enterprise Linux 8.1 Extended Update Support
kernel-0:4.18.0-147.13.2.el8_1
Fixed · RHSA-2020:2199
Red Hat Enterprise Linux 8.1 Extended Update Support
kpatch-patch
Fixed · RHSA-2020:2203
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.67.1.rt56.665.el6rt
Fixed · RHSA-2020:2242
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.54.1.el7
Fixed · RHSA-2020:2289
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.29.2.el6 | Fixed | RHSA-2020:2103 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.8.2.el7 | Fixed | RHSA-2020:2082 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.21.2.el7a | Fixed | RHSA-2020:2104 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1127.8.2.rt56.1103.el7 | Fixed | RHSA-2020:2085 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.88.1.el7 | Fixed | RHSA-2020:2285 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.76.1.el7 | Fixed | RHSA-2020:2277 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.76.1.el7 | Fixed | RHSA-2020:2277 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.76.1.el7 | Fixed | RHSA-2020:2277 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.67.1.el7 | Fixed | RHSA-2020:2214 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | kernel-0:3.10.0-693.67.1.el7 | Fixed | RHSA-2020:2214 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | kernel-0:3.10.0-693.67.1.el7 | Fixed | RHSA-2020:2214 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.54.1.el7 | Fixed | RHSA-2020:2289 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2020:2291 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | kernel-0:3.10.0-1062.26.1.el7 | Fixed | RHSA-2020:2522 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | kpatch-patch | Fixed | RHSA-2020:2519 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-193.1.2.el8_2 | Fixed | RHSA-2020:2102 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-193.1.2.rt13.53.el8_2 | Fixed | RHSA-2020:2171 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2020:2125 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | kernel-0:4.18.0-80.23.2.el8_0 | Fixed | RHSA-2020:2429 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | kernel-0:4.18.0-147.13.2.el8_1 | Fixed | RHSA-2020:2199 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | kpatch-patch | Fixed | RHSA-2020:2203 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.67.1.rt56.665.el6rt | Fixed | RHSA-2020:2242 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.54.1.el7 | Fixed | RHSA-2020:2289 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of the kernel packages as shipped with the Red Hat Enterprise Linux 6 starting with the Red Hat Enterprise Linux 6.7 GA version kernel-2.6.32-573 . Prior Red Hat Enterprise Linux 6 kernel versions are not affected.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. This issue can only be resolved by applying updates.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.08% (0.03083) | 87.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.10% (0.03097) | 86.00th | v5 (v2026.06.15) |
| Dec 28, 2025 | 5.08% (0.05079) | 89.45th | v4 (v2025.03.14) |
| Dec 27, 2025 | 2.79% (0.02788) | 85.70th | v4 (v2025.03.14) |
| Nov 25, 2025 | 5.08% (0.05079) | 89.33th | v4 (v2025.03.14) |
| Nov 21, 2025 | 3.51% (0.03514) | 87.14th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.79% (0.04790) | 88.40th | v4 (v2025.03.14) |
| Oct 28, 2025 | 3.51% (0.03514) | 87.10th | v4 (v2025.03.14) |
| Oct 27, 2025 | 1.91% (0.01909) | 82.69th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.61% (0.00609) | 67.89th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.80% (0.00795) | 82.31th | v3 (v2023.03.01) |
| Apr 12, 2024 | 0.80% (0.00795) | 81.33th | v3 (v2023.03.01) |
| Mar 26, 2024 | 0.58% (0.00585) | 77.69th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.60% (0.00602) | 77.82th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.60% (0.00602) | 75.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.44% (0.00437) | 70.72th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.44% (0.23437) | 94.77th | v2 (v2022.01.01) |
| Feb 3, 2022 | 14.23% (0.14227) | 89.43th | v1 |
| Jan 6, 2022 | 14.23% (0.14227) | 89.30th | v1 |
| Jan 5, 2022 | 3.56% (0.03565) | 82.51th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.56% (0.03565) | 0.00th | v1 |
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-10711 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1825116 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10711 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-10711
- https://security.netapp.com/advisory/ntap-20200608-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4411-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4412-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4413-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4414-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4419-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-10711
- https://www.debian.org/security/2020/dsa-4698 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2020/dsa-4699 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2020/05/12/2 x_refsource_CONFIRMMailing ListPatchThird Party Advisory
Change history (0)
No recorded changes yet.