CVE-2020-10751: Medium severity kernel SELinux vulnerability
A flaw was found in the Linux kernel SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.
At this time, there is no known ability for an attacker to use this to abuse this flaw as capabilities are required to process any 'modify' operation.
Other sources
A flaw was found in the Linux kernel’s SELinux LSM hook implementation, where it anticipated the skb would only contain a single Netlink message. The hook incorrectly validated the first Netlink message in the skb only, to allow or deny the rest of the messages within the skb with the granted permissions and without further processing. At this time, there is no known ability for an attacker to abuse this flaw.
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.rt56.1131.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.rt7.54.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-10751?
CVE-2020-10751 has a medium severity rating due to its impact on the Linux kernel's SELinux implementation.
How do I fix CVE-2020-10751?
To remediate CVE-2020-10751, upgrade to kernel versions 5.7 or later, or apply the relevant patches for affected distributions like Red Hat and Debian.
Which systems are affected by CVE-2020-10751?
CVE-2020-10751 affects various versions of the Linux kernel, specifically those prior to 5.7, as well as multiple Red Hat Enterprise Linux and Debian kernels.
What types of attacks can exploit CVE-2020-10751?
An attacker could exploit CVE-2020-10751 to bypass SELinux protections, potentially allowing unauthorized access or privilege escalation.
Is CVE-2020-10751 related to a specific Linux distribution?
Yes, CVE-2020-10751 specifically affects Red Hat Enterprise Linux and Debian systems with vulnerable versions of the kernel.