First published: Tue Jun 09 2020(Updated: )
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1160.rt56.1131.el7 | 0:3.10.0-1160.rt56.1131.el7 |
redhat/kernel | <0:3.10.0-1160.el7 | 0:3.10.0-1160.el7 |
redhat/kernel | <4.12 | 4.12 |
Linux Kernel | <=4.11.12 | |
Linux Kernel | =4.12 | |
netapp cloud backup | ||
netapp a250 firmware | ||
netapp a250 | ||
netapp fas 500f firmware | ||
netapp fas 500f | ||
netapp aff 500f firmware | ||
netapp aff 500f | ||
netapp solidfire baseboard management controller firmware | ||
netapp solidfire baseboard management controller | ||
Android |
A mitigation to this flaw would be to no longer use IPV6 on affected hardware until the kernel has been updated or to disable Voice Over IP H.323 module. Existing systems that have h323-conntrack-nat kernel module loaded will need to unload the "nf_conntrack_h323" kernel module and blacklist it ( See https://access.redhat.com/solutions/41278 for a guide on how to blacklist modules).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-14305 is high as it allows an unauthenticated remote user to crash the system, leading to a denial of service.
To fix CVE-2020-14305, upgrade to the patched versions of the Linux kernel provided by your distribution, such as kernel-rt version 0:3.10.0-1160.rt56.1131.el7 or kernel version 0:3.10.0-1160.el7.
CVE-2020-14305 is an out-of-bounds memory write flaw in the Linux kernel’s Voice Over IP H.323 connection tracking functionality.
CVE-2020-14305 affects various versions of the Linux kernel, including certain versions of the Red Hat kernel and the Linux kernel up to 4.11.12.
Yes, CVE-2020-14305 can be exploited by an unauthenticated remote user, potentially leading to a system crash.