CVE-2020-12465: Medium severity Linux Linux kernel vulnerability

Published Apr 29, 2020
·
Updated

An array overflow was discovered in mt76addfragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.

Other sources

There was a memory overflow and data corruption flaw seen in the Mediatek MT76 driver module for wifi in mt76addfragment in drivers/net/wireless/mediatek/mt76/dma.c. In this problem an oversized packet with too many rx fragments causes an overflow and a corruption in memory of adjacent pages. A local attacker with special user (or root) privilege can cause a DoS or a leak of internal kernel information.

Reference: https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10

Upstream commit: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2

Red Hat

Affected Software

18 affected components
Linux Linux kernel>=4.16<4.19.111
Linux Linux kernel>=4.20<5.4.26
Linux Linux kernel>=5.5<5.5.10
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Cloud Backup
NetApp Hci Baseboard Management Controller=h300s
NetApp Hci Baseboard Management Controller=h410c
NetApp Hci Baseboard Management Controller=h410s
NetApp Hci Baseboard Management Controller=h500s
NetApp Hci Baseboard Management Controller=h610c
NetApp Hci Baseboard Management Controller=h610s
NetApp Hci Baseboard Management Controller=h615c
NetApp Hci Baseboard Management Controller=h700s
NetApp Solidfire \& Hci Management Node
NetApp Steelstore Cloud Integrated Storage
NetApp Aff Baseboard Management Controller=a700s
NetApp Hci Compute Node
NetApp Solidfire Baseboard Management Controller

Event History

Apr 29, 2020
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
Description
May 5, 2020
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
May 9, 58213
Event
05:03 AM

Frequently Asked Questions

1

What is the vulnerability ID for this array overflow vulnerability?

The vulnerability ID is CVE-2020-12465.

2

Where can I find more information about this vulnerability?

You can find more information about this vulnerability at the following references: [Reference 1](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10), [Reference 2](https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1831703).

3

What is the severity rating of CVE-2020-12465?

The severity rating of CVE-2020-12465 is high with a score of 6.7.

4

What is the affected software?

The affected software includes Linux kernel versions 4.16 to 4.19.111, 4.20 to 5.4.26, and 5.5 to 5.5.10.

5

How can I mitigate this vulnerability?

To mitigate this vulnerability, update your Linux kernel to version 5.5.10 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203