Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10751

Опубликовано: 26 мая 2020
Источник: nvd
CVSS3: 6.1
CVSS2: 3.6
EPSS Низкий

Описание

A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kernel:selinux:*:*:*:*:*:*:*:*
Версия до 5.7 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00093
Низкий

6.1 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-349
CWE-345

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.

CVSS3: 6.1
redhat
около 5 лет назад

A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.

CVSS3: 6.1
debian
около 5 лет назад

A flaw was found in the Linux kernels SELinux LSM hook implementation ...

CVSS3: 6.1
github
около 3 лет назад

A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.

CVSS3: 6.1
fstec
около 5 лет назад

Уязвимость системы принудительного контроля доступа SELinux с модулями безопасности Linux Security Modules (LSM) ядра операционных систем Linux, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 27%
0.00093
Низкий

6.1 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-349
CWE-345