Vulnerability Description
An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.18, < 4.19.118 |
| Netapp | Active Iq Unified Manager | - |
| Netapp | Cloud Backup | - |
| Netapp | Hci Baseboard Management Controller | h300s |
| Netapp | Solidfire \& Hci Management Node | - |
| Netapp | Steelstore Cloud Integrated Storage | - |
| Netapp | Aff Baseboard Management Controller | a700s |
| Netapp | Solidfire Baseboard Management Controller | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlMailing ListThird Party AdvisoryVDB Entry
- https://bugzilla.kernel.org/show_bug.cgi?id=207225ExploitIssue TrackingVendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.7Release NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=99e3aPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/99e3a236dd43d06c65af0a2ef9cb44306aef6e0PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200608-0001/Third Party Advisory
- https://usn.ubuntu.com/4387-1/Third Party Advisory
- https://usn.ubuntu.com/4388-1/Third Party Advisory
- https://usn.ubuntu.com/4389-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlMailing ListThird Party AdvisoryVDB Entry
- https://bugzilla.kernel.org/show_bug.cgi?id=207225ExploitIssue TrackingVendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.7Release NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=99e3aPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/99e3a236dd43d06c65af0a2ef9cb44306aef6e0PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200608-0001/Third Party Advisory
FAQ
What is CVE-2020-12659?
CVE-2020-12659 is a vulnerability with a CVSS score of 6.7 (MEDIUM). An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom vali...
How severe is CVE-2020-12659?
CVE-2020-12659 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12659?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Netapp Active Iq Unified Manager, Netapp Cloud Backup, Netapp Hci Baseboard Management Controller, Netapp Solidfire \& Hci Management Node.