A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2417-1 | linux-4.19 security update |
Debian DLA |
DLA-2494-1 | linux security update |
Debian DSA |
DSA-4774-1 | linux security update |
EUVD |
EUVD-2020-18310 | A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality. |
Ubuntu USN |
USN-4657-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4658-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4660-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4912-1 | Linux kernel (OEM) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.536Z
Reserved: 2020-09-16T00:00:00
Link: CVE-2020-25645
No data.
Status : Modified
Published: 2020-10-13T20:15:12.570
Modified: 2024-11-21T05:18:19.557
Link: CVE-2020-25645
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN