CVE-2020-12465: Medium severity Linux Linux kernel vulnerability
An array overflow was discovered in mt76addfragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
Other sources
There was a memory overflow and data corruption flaw seen in the Mediatek MT76 driver module for wifi in mt76addfragment in drivers/net/wireless/mediatek/mt76/dma.c. In this problem an oversized packet with too many rx fragments causes an overflow and a corruption in memory of adjacent pages. A local attacker with special user (or root) privilege can cause a DoS or a leak of internal kernel information.
Reference: https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10
Upstream commit: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this array overflow vulnerability?
The vulnerability ID is CVE-2020-12465.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Reference 1](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10), [Reference 2](https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b102f0c522cf668c8382c56a4f771b37d011cda2), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1831703).
What is the severity rating of CVE-2020-12465?
The severity rating of CVE-2020-12465 is high with a score of 6.7.
What is the affected software?
The affected software includes Linux kernel versions 4.16 to 4.19.111, 4.20 to 5.4.26, and 5.5 to 5.5.10.
How can I mitigate this vulnerability?
To mitigate this vulnerability, update your Linux kernel to version 5.5.10 or later.