5.5
CVSSv3

CVE-2020-12656

Published: 05/05/2020 Updated: 14/05/2024
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel up to and including 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that on unloading a specific kernel module some memory is leaked, but loading kernel modules is a privileged operation. A user could also write a kernel module to consume any amount of memory they like and load that replicating the effect of this bug

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

canonical ubuntu linux 18.04

canonical ubuntu linux 14.04

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

opensuse leap 15.1

opensuse leap 15.2

Vendor Advisories

A flaw was found in the AMD Cryptographic Co-processor driver in the Linux kernel An attacker, able to send invalid SHA type commands, could cause the system to crash The highest threat from this vulnerability is to system availability (CVE-2019-18808) A flaw was found in the Linux kernel The CX23888 Integrated Consumer Infrared Controller prob ...