{"id":"MGASA-2020-0392","summary":"Updated kernel packages fix security vulnerabilities","details":"A flaw was found in the way the Linux kernel Bluetooth implementation handled\nL2CAP packets with A2MP CID. A remote attacker in adjacent range could use\nthis flaw to crash the system causing denial of service or potentially execute\narbitrary code on the system by sending a specially crafted L2CAP packet. The\nhighest threat from this vulnerability is to data confidentiality and\nintegrity as well as system availability (CVE-2020-12351).\n\nAn information leak flaw was found in the way the Linux kernel's Bluetooth\nstack implementation handled initialization of stack memory when handling\ncertain AMP packets. A remote attacker in adjacent range could use this flaw\nto leak small portions of stack memory on the system by sending a specially\ncrafted AMP packets. The highest threat from this vulnerability is to data\nconfidentiality (CVE-2020-12352).\n\nA flaw was found in the Linux kernel before 5.9-rc4. A failure of the file\nsystem metadata validator in XFS can cause an inode with a valid,\nuser-creatable extended attribute to be flagged as corrupt. This can lead to\nthe filesystem being shutdown, or otherwise rendered inaccessible until it is\nremounted, leading to a denial of service. The highest threat from this\nvulnerability is to system availability (CVE-2020-14385).\n\nA flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be\nexploited to gain root privileges from unprivileged processes. The highest\nthreat from this vulnerability is to data confidentiality and integrity\n(CVE-2020-14386).\n\nA flaw was found in the Linux kernel in versions before 5.9-rc6. When changing\nscreen size, an out-of-bounds memory write can occur leading to memory\ncorruption or a denial of service. Due to the nature of the flaw, privilege\nescalation cannot be fully ruled out (CVE-2020-14390).\n\nA heap buffer overflow flaw was found in the way the Linux kernel’s Bluetooth\nimplementation processed extended advertising report events. This flaw allows\na remote attacker in an adjacent range to crash the system, causing a denial\nof service or to potentially execute arbitrary code on the system by sending a\nspecially crafted Bluetooth packet. The highest threat from this vulnerability\nis to confidentiality, integrity, as well as system availability\n(CVE-2020-24490).\n\nIn the Linux kernel through 5.8.7, local attackers able to inject conntrack\nnetlink configuration could overflow a local buffer, causing crashes or\ntriggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter\nin net/netfilter/nf_conntrack_netlink.c (CVE-2020-25211).\n\nget_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7\nallows privilege escalation because of incorrect reference counting (caused by\ngate page mishandling) of the struct page that backs the vsyscall page. The\nresult is a refcount underflow. This can be triggered by any 64-bit process\nthat can use ptrace() or process_vm_readv() (CVE-2020-25221).\n\nThe rbd block device driver in drivers/block/rbd.c in the Linux kernel through\n5.8.9 used incomplete permission checking for access to rbd devices, which\ncould be leveraged by local attackers to map or unmap rbd block devices\n(CVE-2020-25284).\n\nA race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux\nkernel before 5.8.8 could be used by local attackers to corrupt memory, cause\na NULL pointer dereference, or possibly have unspecified other impact\n(CVE-2020-25285).\n\nA flaw was found in the Linux kernel's implementation of biovecs in versions\nbefore 5.9-rc7. A zero-length biovec request issued by the block subsystem\ncould cause the kernel to enter an infinite loop, causing a denial of\nservice. This flaw allows a local attacker with basic privileges to issue\nrequests to a block device, resulting in a denial of service. The highest\nthreat from this vulnerability is to system availability (CVE-2020-25641).\n\nA flaw was found in the HDLC_PPP module of the Linux kernel in versions before\n5.9-rc7. Memory corruption and a read overflow is caused by improper input\nvalidation in the ppp_cp_parse_cr function which can cause the system to crash\nor cause a denial of service. The highest threat from this vulnerability is to\ndata confidentiality and integrity as well as system availability\n(CVE-2020-25643).\n\nA flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic\nbetween two Geneve endpoints may be unencrypted when IPsec is configured to\nencrypt traffic for the specific UDP port used by the GENEVE tunnel allowing\nanyone between the two endpoints to read the traffic unencrypted. The main\nthreat from this vulnerability is to data confidentiality (CVE-2020-25645).\n\nAlso, the xtables-addons package has been updated to version 3.11.\n","modified":"2026-04-16T04:42:28.750500512Z","published":"2020-10-21T13:07:53Z","upstream":["CVE-2020-12351","CVE-2020-12352","CVE-2020-14385","CVE-2020-14386","CVE-2020-14390","CVE-2020-24490","CVE-2020-25211","CVE-2020-25221","CVE-2020-25284","CVE-2020-25285","CVE-2020-25641","CVE-2020-25643","CVE-2020-25645"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0392.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27443"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-14385"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-14386"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-14390"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25211"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25221"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25284"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25285"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25641"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25643"},{"type":"ADVISORY","url":"https://www.linuxkernelcves.com/cves/CVE-2020-25645"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2020-12351"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2020-12352"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2020-24490"}],"affected":[{"package":{"name":"kernel","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/kernel?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.7.19-3.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0392.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.24-6.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0392.json"}},{"package":{"name":"xtables-addons","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/xtables-addons?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.11-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0392.json"}},{"package":{"name":"kmod-xtables-addons","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/kmod-xtables-addons?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.11-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0392.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}