CVE-2020-26088

Description

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.013

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-4.12.14-16.31.1.x86_64.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-4.12.14-16.31.1.x86_64.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-debuginfo-4.12.14-16.31.1.x86_64.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debuginfo-4.12.14-16.31.1.x86_64.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debugsource-4.12.14-16.31.1.x86_64.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-devel-4.12.14-16.31.1.x86_64.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-azure-4.12.14-16.31.1.noarch.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-azure-4.12.14-16.31.1.noarch.rpmLinux
SUSE-SU-2020:2907-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-azure-4.12.14-16.31.1.x86_64.rpmLinux
Linux kernel (USN-4578-1) linux-image-gcp_4.15.0.1086.87_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-gke_4.15.0.1072.76_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-gke_4.15.0.1086.87_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-kvm_4.15.0.1077.73_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-oem_4.15.0.120.121_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-oem_4.15.0.1099.103_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-azure_4.15.0.1098.92_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-oracle_4.15.0.1056.46_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-aws-hwe_4.15.0.1085.81_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-generic_4.15.0.121.108_i386.debLinux
Linux kernel (USN-4578-1) linux-image-generic_4.15.0.121.108_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-virtual_4.15.0.121.108_i386.debLinux
Linux kernel (USN-4578-1) linux-image-virtual_4.15.0.121.108_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-gke-4.15_4.15.0.1072.76_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-lowlatency_4.15.0.121.108_i386.debLinux
Linux kernel (USN-4578-1) linux-image-lowlatency_4.15.0.121.108_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-aws-lts-18.04_4.15.0.1086.88_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-gcp-lts-18.04_4.15.0.1086.104_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1072-gke_4.15.0-1072.76_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1077-kvm_4.15.0-1077.79_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1085-aws_4.15.0-1085.90~16.04.1_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1086-aws_4.15.0-1086.91_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1086-gcp_4.15.0-1086.98_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1086-gcp_4.15.0-1086.98~16.04.1_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1099-oem_4.15.0-1099.109_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-azure-lts-18.04_4.15.0.1099.72_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-oracle-lts-18.04_4.15.0.1057.67_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1098-azure_4.15.0-1098.109~16.04.1_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1099-azure_4.15.0-1099.110_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-generic-hwe-16.04_4.15.0.120.121_i386.debLinux
Linux kernel (USN-4578-1) linux-image-generic-hwe-16.04_4.15.0.120.121_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-virtual-hwe-16.04_4.15.0.120.121_i386.debLinux
Linux kernel (USN-4578-1) linux-image-virtual-hwe-16.04_4.15.0.120.121_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1056-oracle_4.15.0-1056.61~16.04.1_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-1057-oracle_4.15.0-1057.62_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-120-generic_4.15.0-120.122~16.04.1_i386.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-120-generic_4.15.0-120.122~16.04.1_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-121-generic_4.15.0-121.123_i386.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-121-generic_4.15.0-121.123_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-lowlatency-hwe-16.04_4.15.0.120.121_i386.debLinux
Linux kernel (USN-4578-1) linux-image-lowlatency-hwe-16.04_4.15.0.120.121_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-120-lowlatency_4.15.0-120.122~16.04.1_i386.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-120-lowlatency_4.15.0-120.122~16.04.1_amd64.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-121-lowlatency_4.15.0-121.123_i386.debLinux
Linux kernel (USN-4578-1) linux-image-4.15.0-121-lowlatency_4.15.0-121.123_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234