CVE-2020-26088: Medium severity Linux Linux kernel vulnerability
A missing CAPNETRAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.8.2Patch CID-26896f01467a
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26088?
The severity of CVE-2020-26088 is considered medium, as it allows local attackers to bypass security mechanisms.
How do I fix CVE-2020-26088?
To fix CVE-2020-26088, update the Linux kernel to version 5.8.2 or later.
Which systems are affected by CVE-2020-26088?
CVE-2020-26088 affects various Linux kernel versions prior to 5.8.2, including certain Debian and openSUSE versions.
Can CVE-2020-26088 be exploited remotely?
CVE-2020-26088 requires local access to the machine for exploitation, as it involves creating raw sockets.
What is the impact of CVE-2020-26088?
The impact of CVE-2020-26088 includes the potential for local users to create raw sockets and bypass security controls.