CVE-2020-14305: High severity Google Android vulnerability

Published Jun 9, 2020
·
Updated

A flaw memory corruption in the Linux kernel Voice over IP h323-conntrack-nat module was found. An attacker could use this flaw to corrupt the memory. For reproducing, need to establish connection to the port 1720 that is being used during call setup negotiation. For ipv4 no crash (kernel panic), so for detecting corruption need to use ipv6. The corruption happens for fields of struct nfctext (usually nfctnat is located after nfconnhelp, but possibly nfconnnat and other that located in memory right after nfconnhelp). In most cases the overlapping bytes were zero (if without debug options), so attacker cannot control directly what is being written to the corrupted memory, but at least one numerical value could be modified with tpktlen (so attacker can change TCP/IP packet payload size to control what is being written to some corrupted Int value).

The patch is: https://patchwork.ozlabs.org/project/netfilter-devel/patch/c2385b5c-309c-cc64-2e10-a0ef62897502@virtuozzo.com/

Other sources

An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Affected Software

15 affected componentsFixes available
redhat/kernel-rt<0:3.10.0-1160.rt56.1131.el7
0:3.10.0-1160.rt56.1131.el7
redhat/kernel<0:3.10.0-1160.el7
0:3.10.0-1160.el7
redhat/kernel<4.12
4.12
Google Android
Linux Linux kernel<=4.11.12
Linux Linux kernel=4.12
NetApp Cloud Backup
NetApp A250 Firmware
NetApp A250
NetApp Fas 500f Firmware
NetApp Fas 500f
NetApp Aff 500f Firmware
NetApp Aff 500f
NetApp Solidfire Baseboard Management Controller Firmware
NetApp Solidfire Baseboard Management Controller

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-1160.rt56.1131.el7
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-1160.el7
  3. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 4.12
  4. Configuration

    Do not use IPv6 on affected hardware until the kernel has been updated (disable IPv6 on the host until you upgrade to a fixed kernel).

    IPv6 networking on affected hosts use_ipv6 = disabled
  5. Configuration

    Unload the h323-conntrack-nat module (nf_conntrack_h323) if currently loaded and blacklist it to prevent future loading (unload the module and add it to the system's module blacklist).

    Linux kernel module nf_conntrack_h323 loaded/blacklisted = unloaded and blacklisted
  6. Compensating control

    Block or restrict IPv6 access to TCP port 1720 at network perimeter/firewalls or otherwise restrict access to port 1720 for IPv6 to mitigate exploitation until hosts are updated.

Event History

Jun 9, 2020
CVE Published
12:00 AM
Dec 2, 2020
CVE Published
via MITRE·12:48 AM
Data Sourced
via MITRE·12:48 AM
DescriptionWeakness
Jun 7, 2021
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-14305?

The severity of CVE-2020-14305 is high as it allows an unauthenticated remote user to crash the system, leading to a denial of service.

2

How do I fix CVE-2020-14305?

To fix CVE-2020-14305, upgrade to the patched versions of the Linux kernel provided by your distribution, such as kernel-rt version 0:3.10.0-1160.rt56.1131.el7 or kernel version 0:3.10.0-1160.el7.

3

What type of vulnerability is CVE-2020-14305?

CVE-2020-14305 is an out-of-bounds memory write flaw in the Linux kernel’s Voice Over IP H.323 connection tracking functionality.

4

Which systems are affected by CVE-2020-14305?

CVE-2020-14305 affects various versions of the Linux kernel, including certain versions of the Red Hat kernel and the Linux kernel up to 4.11.12.

5

Can CVE-2020-14305 be exploited remotely?

Yes, CVE-2020-14305 can be exploited by an unauthenticated remote user, potentially leading to a system crash.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203