CVE-2020-10751
Last modified
CVE-2020-10751 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kernel | Selinux | < 5.7 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server | 8.0 |
References
- http://www.openwall.com/lists/oss-security/2020/05/27/3Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10751Issue Tracking, Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/04/30/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/05/27/3Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10751Issue Tracking, Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/04/30/5Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10751?
How severe is CVE-2020-10751?
How do I fix CVE-2020-10751?
Are you affected by CVE-2020-10751?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
