CVE-2020-14305
Summary
| CVE | CVE-2020-14305 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-02 01:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [v4.10] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 - Patchwork |
MISC |
patchwork.ozlabs.org |
Mailing List, Patch, Third Party Advisory |
| [OVZ-7188] Crash kernel 3.10.0-1062.4.2.vz7.116.7 - bugs.openvz.org |
MISC |
bugs.openvz.org |
Exploit, Third Party Advisory |
| [v4.10] netfilter: nf_conntrack_h323: lost .data_len definition for Q.931/ipv6 - Patchwork |
|
patchwork.ozlabs.org |
|
| 1850716 – (CVE-2020-14305) CVE-2020-14305 kernel: memory corruption in Voice over IP nf_conntrack_h323 module |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| CVE-2020-14305 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375284 EulerOS Security Update for kernel (EulerOS-SA-2021-1311)
- 390217 Oracle Managed Virtualization (VM) Server for x86 Security Update for Unbreakable Enterprise kernel (OVMSA-2021-0001)
- 390234 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0001)
- 610344 Google Android Devices June 2021 Security Patch Missing
- 610354 Google Android July 2021 Security Patch Missing for LGE
- 610355 Google Android July 2021 Security Patch Missing for Samsung
- 610358 Google Android July 2021 Security Patch Missing for Huawei EMUI
- 670185 EulerOS Security Update for kernel (EulerOS-SA-2021-1684)
- 751451 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:3935-1)