Back

HIGH

kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow

Published Oct 6, 2020

Description

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products

Remediation

Red Hat statement

This flaw is rated as a having Moderate impact, because the bug can be triggered only if PPP protocol enabled.

Red Hat mitigation

To mitigate this issue, prevent modules hdlc_ppp, syncppp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 6, 2020
Updated Aug 4, 2024
Reserved Sep 16, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 25, 2020