Skip to content

kernel CVE-2020-25211

High
etungsten published GHSA-x776-q533-gfwx Jan 15, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.0.5

Patched versions

1.0.5

Description

A local attacker, able to inject conntrack netlink configuration, could overflow a local buffer causing crashes or triggering the use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c.

Severity

High

CVE ID

CVE-2020-25211

Weaknesses

No CWEs