CVE-2020-10720
published 2020-09-03CVE-2020-10720: A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.8th percentile
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| linux | linux_kernel | < 5.2 | 5.2 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hx2j-322m-8267: A flaw was found in the Linux kernel's implementation of GRO in versions before 5
ghsa_unreviewed·2022-05-24
CVE-2020-10720 [MEDIUM] GHSA-hx2j-322m-8267: A flaw was found in the Linux kernel's implementation of GRO in versions before 5
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
OSV
CVE-2020-10720: A flaw was found in the Linux kernel's implementation of GRO in versions before 5
osv·2020-09-03·CVSS 5.5
CVE-2020-10720 [MEDIUM] CVE-2020-10720: A flaw was found in the Linux kernel's implementation of GRO in versions before 5
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
Debian
CVE-2020-10720: linux - A flaw was found in the Linux kernel's implementation of GRO in versions before ...
vendor_debian·2020·CVSS 5.5
CVE-2020-10720 [MEDIUM] CVE-2020-10720: linux - A flaw was found in the Linux kernel's implementation of GRO in versions before ...
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
Red Hat
kernel: use-after-free read in napi_gro_frags() in the Linux kernel
vendor_redhat·2019-12-09·CVSS 5.5
CVE-2020-10720 [MEDIUM] CWE-416 kernel: use-after-free read in napi_gro_frags() in the Linux kernel
kernel: use-after-free read in napi_gro_frags() in the Linux kernel
A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.
A flaw was found in the Linux kernel’s implementation of GRO. This flaw allows an attacker with local access to crash the system.
Statement: This issue is rated as having Moderate impact because it appears to be limited to only to a crash.
Mitigation: Disabling GSO on the cards using ethtool will prevent this codepath from being taken.
Package: kernel (Red Hat Enterprise Linux 5) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterpris
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1781204https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4270d6795b0580287453ea55974d948393e66efhttps://bugzilla.redhat.com/show_bug.cgi?id=1781204https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4270d6795b0580287453ea55974d948393e66ef
2020-09-03
Published