CVE-2020-25860: High severity pengutronix rauc vulnerability
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25860?
CVE-2020-25860 is considered a high severity vulnerability due to the potential for unauthorized modification of update files.
How do I fix CVE-2020-25860?
To fix CVE-2020-25860, upgrade the Pengutronix RAUC update client to version 1.5 or higher.
What type of vulnerability is CVE-2020-25860?
CVE-2020-25860 is a Time-of-Check Time-of-Use (TOCTOU) vulnerability.
Who is affected by CVE-2020-25860?
CVE-2020-25860 affects all versions of the Pengutronix RAUC update client prior to version 1.5.
What impact does CVE-2020-25860 have on systems?
CVE-2020-25860 allows an attacker to modify an update file just before installation, potentially leading to system compromise.