Description
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted link; rather sending the data unencrypted. This would allow anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Published: 2020-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2241-1 linux security update
Debian DLA Debian DLA DLA-2241-2 linux security update
EUVD EUVD EUVD-2020-12580 A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted link; rather sending the data unencrypted. This would allow anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Ubuntu USN Ubuntu USN USN-4388-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4390-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4391-1 Linux kernel vulnerabilities
History

No history.

Subscriptions

Linux Linux Kernel
Redhat Enterprise Linux Enterprise Mrg Rhel Extras Rt
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T06:46:30.814Z

Reserved: 2019-11-27T00:00:00.000Z

Link: CVE-2020-1749

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-09T15:15:10.300

Modified: 2024-11-21T05:11:18.210

Link: CVE-2020-1749

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-04T01:29:00Z

Links: CVE-2020-1749 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses