CVE-2020-25645: High severity linux kernel vulnerability
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Other sources
A flaw was found in the Linux kernel. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
A flaw was found in the Linux kernel's implementation of GENEVE tunnels combined with IPsec. The traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel. This would allow anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=34beb21594519ce64a55a498c2fe7d567bc1ca20
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-25645?
CVE-2020-25645 has a high severity rating due to the potential for unencrypted traffic between Geneve endpoints.
How do I fix CVE-2020-25645?
To address CVE-2020-25645, you should upgrade to the Linux kernel version 5.9 or later.
Which versions of the Linux kernel are affected by CVE-2020-25645?
CVE-2020-25645 affects Linux kernel versions prior to 5.9-rc7.
What impact does CVE-2020-25645 have on network security?
CVE-2020-25645 could allow attackers to intercept and read unencrypted traffic between Geneve tunnel endpoints.
Is IPsec configuration sufficient to protect against CVE-2020-25645?
No, IPsec configuration may not provide adequate protection for traffic on specific UDP ports used by the GENEVE tunnel as per CVE-2020-25645.