In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2241-1 | linux security update |
Debian DLA |
DLA-2241-2 | linux security update |
Debian DLA |
DLA-2242-1 | linux-4.9 security update |
Debian DSA |
DSA-4667-1 | linux security update |
Debian DSA |
DSA-4698-1 | linux security update |
EUVD |
EUVD-2020-3347 | In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls. |
Ubuntu USN |
USN-4342-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4344-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4345-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4364-1 | Linux kernel vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:21:14.585Z
Reserved: 2020-03-24T00:00:00
Link: CVE-2020-10942
No data.
Status : Modified
Published: 2020-03-24T22:15:12.470
Modified: 2024-11-21T04:56:25.320
Link: CVE-2020-10942
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN