ZeroHour

CVE-2020-25643

CVSS 3.1
7.2 high
EPSS
3%p88
Published
()
Modified
Description

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vendors
linuxredhatopensusedebiannetappstarwindsoftware
Products
linux kernel, enterprise linux, leap, debian linux, h410c firmware, starwind virtual san
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.