Lucene search

K
redhatcveRedhat.comRH:CVE-2020-12659
HistoryMay 07, 2020 - 12:40 p.m.

CVE-2020-12659

2020-05-0712:40:28
redhat.com
access.redhat.com
12

0.001 Low

EPSS

Percentile

31.4%

An out-of-bounds (OOB) memory access flaw was found in the Network XDP (the eXpress Data Path) module in the Linux kernel’s xdp_umem_reg function in net/xdp/xdp_umem.c. When a user with special user privilege of CAP_NET_ADMIN (or root) calls setsockopt to register umem ring on XDP socket, passing the headroom value larger than the available space in the chunk, it leads to an out-of-bounds write, causing panic or possible memory corruption. This flaw may lead to privilege escalation if a local end-user is granted permission to influence the execution of code in this manner.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.