kernel: x25_bind out-of-bounds read
Published May 6, 2021
7.8
HIGHCVSS 3.1
EPSS 0.41%
Description
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version v5.12-rc5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- ≥ 2.6.12 · < 4.4.248
- ≥ 4.5 · < 4.9.248
- ≥ 4.10 · < 4.14.211
- ≥ 4.15 · < 4.19.162
- ≥ 4.20 · < 5.4.82
- ≥ 5.5 · < 5.9.13
Configuration 2
- n/a
Configuration 3
Running on/with
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
There was no shipped kernel version affected by this problem. These files are not built in our source code.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2020-35519 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1908251 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23186 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-35519
- https://security.netapp.com/advisory/ntap-20210618-0009/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-35519
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-35519 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1908251 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23186 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-35519 | ||
| https://security.netapp.com/advisory/ntap-20210618-0009/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-35519 |
Change history (0)
No recorded changes yet.