MEDIUM · 5.3

CVE-2020-12888

The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

Vulnerability Description

The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 5.6.13
FedoraprojectFedora31
OpensuseLeap15.1
DebianDebian Linux9.0
CanonicalUbuntu Linux14.04
NetappActive Iq Unified Manager-
NetappCloud Backup-
NetappElement Software-
NetappHci Management Node-
NetappSolidfire-
NetappSteelstore Cloud Integrated Storage-
NetappSolidfire Baseboard Management Controller Firmware-
NetappSolidfire Baseboard Management Controller-
NetappBootstrap Os-
NetappHci Compute Node-
NetappA700S Firmware-
NetappA700S-
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12888?

CVE-2020-12888 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

How severe is CVE-2020-12888?

CVE-2020-12888 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-12888?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Opensuse Leap, Debian Debian Linux, Canonical Ubuntu Linux.