Skip to content

kernel CVE-2020-14386

High
iliana published GHSA-53mq-2mw5-rjcr Sep 4, 2020

Package

kernel (bottlerocket)

Affected versions

< 1.0.1

Patched versions

1.0.1

Description

An issue has been reported in the Linux kernel's handling of raw sockets. This issue can be used locally to cause denial of service or local privilege escalation from unprivileged processes or from containers with the CAP_NET_RAW capability enabled.

https://marc.info/?l=linux-netdev&m=159915549623724&w=2
https://www.openwall.com/lists/oss-security/2020/09/03/3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14386

Severity

High

CVE ID

CVE-2020-14386

Weaknesses

No CWEs