Rapid7 Vulnerability & Exploit Database

Red Hat: CVE-2020-25211: Important: kernel security and bug fix update (Multiple Advisories)

Back to Search

Red Hat: CVE-2020-25211: Important: kernel security and bug fix update (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:L/Au:N/C:N/I:P/A:P)
Published
09/09/2020
Created
01/06/2021
Added
01/05/2021
Modified
07/21/2021

Description

In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.

Solution(s)

  • redhat-upgrade-kernel
  • redhat-upgrade-kernel-rt
  • redhat-upgrade-kpatch-patch-4_18_0-147_13_2
  • redhat-upgrade-kpatch-patch-4_18_0-147_13_2-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-147_13_2-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-147_20_1
  • redhat-upgrade-kpatch-patch-4_18_0-147_20_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-147_20_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-147_24_2
  • redhat-upgrade-kpatch-patch-4_18_0-147_24_2-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-147_24_2-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-147_27_1
  • redhat-upgrade-kpatch-patch-4_18_0-147_27_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-147_27_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-147_32_1
  • redhat-upgrade-kpatch-patch-4_18_0-147_32_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-147_32_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-147_34_1
  • redhat-upgrade-kpatch-patch-4_18_0-147_34_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-147_34_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-147_5_1
  • redhat-upgrade-kpatch-patch-4_18_0-147_8_1
  • redhat-upgrade-kpatch-patch-4_18_0-193
  • redhat-upgrade-kpatch-patch-4_18_0-193-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_13_2
  • redhat-upgrade-kpatch-patch-4_18_0-193_13_2-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_13_2-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_14_3
  • redhat-upgrade-kpatch-patch-4_18_0-193_14_3-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_14_3-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_19_1
  • redhat-upgrade-kpatch-patch-4_18_0-193_19_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_19_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_1_2
  • redhat-upgrade-kpatch-patch-4_18_0-193_1_2-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_1_2-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_28_1
  • redhat-upgrade-kpatch-patch-4_18_0-193_28_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_28_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_29_1
  • redhat-upgrade-kpatch-patch-4_18_0-193_29_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_29_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_37_1
  • redhat-upgrade-kpatch-patch-4_18_0-193_37_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_37_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_40_1
  • redhat-upgrade-kpatch-patch-4_18_0-193_40_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_40_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_41_1
  • redhat-upgrade-kpatch-patch-4_18_0-193_41_1-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_41_1-debugsource
  • redhat-upgrade-kpatch-patch-4_18_0-193_6_3
  • redhat-upgrade-kpatch-patch-4_18_0-193_6_3-debuginfo
  • redhat-upgrade-kpatch-patch-4_18_0-193_6_3-debugsource

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;