CVE-2020-12465
published 2020-04-29CVE-2020-12465: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An…
PriorityP427medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.8th percentile
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.5.13-1 (bookworm) | linux 5.5.13-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 4.16 < 4.19.111 | 4.19.111 |
| linux | linux_kernel | >= 4.20 < 5.4.26 | 5.4.26 |
| linux | linux_kernel | >= 5.5 < 5.5.10 | 5.5.10 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-3_on_cbl_mariner_1.0 | — | — |
| netapp | aff_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q479-f6q7-24rp: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma
ghsa_unreviewed·2022-05-24
CVE-2020-12465 [HIGH] CWE-120 GHSA-q479-f6q7-24rp: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
OSV
CVE-2020-12465: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma
osv·2020-04-29·CVSS 6.7
CVE-2020-12465 [MEDIUM] CVE-2020-12465: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
Microsoft
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10 aka CID-b102f0c522cf. An oversized packet with too many rx fragments
vendor_msrc·2020-04-14·CVSS 6.7
CVE-2020-12465 [MEDIUM] CWE-120 An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10 aka CID-b102f0c522cf. An oversized packet with too many rx fragments
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10 aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional prod
Red Hat
kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c
vendor_redhat·2020-03-03·CVSS 6.7
CVE-2020-12465 [MEDIUM] CWE-120 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c
kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
A memory overflow and data corruption flaw were found in the Mediatek MT76 driver module for WiFi in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c. An oversized packet with too many rx fragments causes an overflow and corruption in memory of adjacent pages. A local attacker with a special user or root privileges can cause a denial of service or a leak of internal kernel information.
Mitigation: Mitigation for this issue is to skip loading
Debian
CVE-2020-12465: linux - An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/me...
vendor_debian·2020·CVSS 6.7
CVE-2020-12465 [MEDIUM] CVE-2020-12465: linux - An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/me...
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
Suricata
ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway Remote Code Execution
suricata·2018-08-24
ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway Remote Code Execution
ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway Remote Code Execution
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway Remote Code Execution"; flow:established,to_server; http.uri; content:"/manage_domains_save_data.json.php?cache="; http.request_body; content:"%24%28"; reference:url,github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/microfocus_secure_messaging_gateway.rb; classtype:attempted-user; sid:2026037; rev:3; metadata:affected_product PHP, attack_target Web_Server, created_at 2018_08_24, cve cve_2018_12465, deployment Datacenter, signature_severity Major, updated_at 2020_08_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_techniqu
No public exploits indexed.
Bugzilla
CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c [fedora-all]
bugzilla·2020-05-05·CVSS 6.7
CVE-2020-12465 [MEDIUM] CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c [fedora-all]
CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c
bugzilla·2020-05-05·CVSS 6.7
CVE-2020-12465 [MEDIUM] CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c
CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c
There was a memory overflow and data corruption flaw seen in the Mediatek MT76 driver module for wifi in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c. In this problem an oversized packet with too many rx fragments causes an overflow and a corruption in memory of adjacent pages. A local attacker with special user (or root) privilege can cause a DoS or a leak of internal kernel information.
Reference:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10
Upstream commit:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2
Discussion:
Created kernel tracking bugs for this issue:
Affects:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2https://github.com/torvalds/linux/commit/b102f0c522cf668c8382c56a4f771b37d011cda2https://security.netapp.com/advisory/ntap-20200608-0001/https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2https://github.com/torvalds/linux/commit/b102f0c522cf668c8382c56a4f771b37d011cda2https://security.netapp.com/advisory/ntap-20200608-0001/
2020-04-29
Published