Vulnerability Description
gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that on unloading a specific kernel module some memory is leaked, but loading kernel modules is a privileged operation. A user could also write a kernel module to consume any amount of memory they like and load that replicating the effect of this bug
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 5.6.10 |
| Canonical | Ubuntu Linux | 14.04 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.htmlMailing ListThird Party Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=206651Issue TrackingVendor Advisory
- https://usn.ubuntu.com/4483-1/Third Party Advisory
- https://usn.ubuntu.com/4485-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.htmlMailing ListThird Party Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=206651Issue TrackingVendor Advisory
- https://usn.ubuntu.com/4483-1/Third Party Advisory
- https://usn.ubuntu.com/4485-1/Third Party Advisory
FAQ
What is CVE-2020-12656?
CVE-2020-12656 is a vulnerability with a CVSS score of 5.5 (MEDIUM). gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This...
How severe is CVE-2020-12656?
CVE-2020-12656 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12656?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Opensuse Leap.