cbcvebase.
CVE-2020-25211
published 2020-09-09

CVE-2020-25211: In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering…

PriorityP424medium6CVSS 3.1
AVLACLPRHUINSUCNIHAH
EPSS
0.57%
43.2th percentile
In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.8.14-1 (bookworm)linux 5.8.14-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel<= 5.8.7
linuxlinux_kernel>= 0 < 5.8.14-15.8.14-1
linuxlinux_kernel>= 0 < 5.8.14-15.8.14-1
linuxlinux_kernel>= 0 < 5.8.14-15.8.14-1
linuxlinux_kernel>= 0 < 5.8.14-15.8.14-1
linuxlinux_kernel>= 0 < 4.4.0-197.2294.4.0-197.229
linuxlinux_kernel>= 0 < 4.15.0-128.1314.15.0-128.131
linuxlinux_kernel>= 0 < 4.15.0-126.1294.15.0-126.129
linuxlinux_kernel>= 0 < 5.4.0-58.645.4.0-58.64
linuxlinux_kernel>= 0 < 5.4.0-56.625.4.0-56.62
msrccm1_kernel_5.4.91-3_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.