• CVE-2020-10751

发布时间: 2022年4月29日

修改时间: 2022年4月29日

概要

A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.

CVSS v3 指标

NVD openEuler
CVSS评分 6.1 6.1
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality High High
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-1405 A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing. 2022年4月29日

影响产品

产品 状态
KY3.4-4A libselinux Unaffected
KY3.4-5 libselinux Unaffected
KY3.5.1 libselinux Unaffected