cbcvebase.
CVE-2020-10751
published 2020-05-26

CVE-2020-10751: A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single…

PriorityP427medium6.1CVSS 3.1
AVLACLPRLUINSUCHILAN
EPSS
0.35%
27.4th percentile
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.6.14-1 (bookworm)linux 5.6.14-1 (bookworm)
googleandroid
kernelselinux< 5.75.7
linuxlinux_kernel>= 0 < 5.6.14-15.6.14-1
linuxlinux_kernel>= 0 < 5.6.14-15.6.14-1
linuxlinux_kernel>= 0 < 5.6.14-15.6.14-1
linuxlinux_kernel>= 0 < 5.6.14-15.6.14-1
linuxlinux_kernel>= 0 < 4.4.0-184.2144.4.0-184.214
linuxlinux_kernel>= 0 < 4.15.0-106.1074.15.0-106.107
linuxlinux_kernel>= 0 < 5.4.0-37.415.4.0-37.41
redhatenterprise_linux_server
redhatenterprise_linux_server
the_linux_foundationkernel

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.