CVE-2020-12888Improper Handling of Exceptional Conditions in Kernel

Severity
5.3MEDIUMNVD
OSV5.5
EPSS
0.1%
top 73.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15
Latest updateMay 24

Description

The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 0.8 | Impact: 4.0

Affected Packages4 packages

Debianlinux/linux_kernel< 5.8.7-1+3
Ubuntulinux/linux_kernel< 4.15.0-118.119+2
NVDlinux/linux_kernel5.6.13
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 20.04, Fedora 31, 32

🔴Vulnerability Details

7
GHSA
GHSA-3rqr-2pp7-2956: The VFIO PCI driver in the Linux kernel through 52022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-04-01
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities2020-09-24
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2020-09-23
OSV
CVE-2020-12888: The VFIO PCI driver in the Linux kernel through 52020-05-15

📋Vendor Advisories

6
Ubuntu
Linux kernel vulnerabilities2022-04-01
Ubuntu
Linux kernel vulnerabilities2020-09-24
Ubuntu
Linux kernel vulnerabilities2020-09-23
Red Hat
Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario2020-05-14
Microsoft
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.2020-05-12

💬Community

2
Bugzilla
CVE-2020-12888 kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario [fedora-all]2020-05-15
Bugzilla
CVE-2020-12888 Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario2020-05-15
CVE-2020-12888 — Linux Kernel vulnerability | cvebase