CVE-2020-12465Classic Buffer Overflow in Kernel

Severity
6.7MEDIUMNVD
EPSS
0.2%
top 61.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29
Latest updateMay 24

Description

An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q479-f6q7-24rp: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma2022-05-24
CVEList
CVE-2020-12465: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma2020-04-29
OSV
CVE-2020-12465: An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma2020-04-29

📋Vendor Advisories

3
Microsoft
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10 aka CID-b102f0c522cf. An oversized packet with too many rx fragments2020-04-14
Red Hat
kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c2020-03-03
Debian
CVE-2020-12465: linux - An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/me...2020

💬Community

2
Bugzilla
CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c [fedora-all]2020-05-05
Bugzilla
CVE-2020-12465 kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c2020-05-05
CVE-2020-12465 — Classic Buffer Overflow in Kernel | cvebase