imPC@ndo IT

Tracker / CVE-2020-25643

CVE-2020-25643

High 7.2

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products and versions

debian debian_linux
linux linux_kernel
linux linux_kernel · 2.6.29 → 4.4.238
linux linux_kernel · 4.10 → 4.14.200
linux linux_kernel · 4.15 → 4.19.148
linux linux_kernel · 4.20 → 5.4.68
linux linux_kernel · 4.5 → 4.9.238
linux linux_kernel · 5.5 → 5.8.12
netapp h410c_firmware
opensuse leap
redhat enterprise_linux
starwindsoftware starwind_virtual_san

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References