Vulnerability Name:

CVE-2020-25639 (CCN-194592)

Assigned:2020-09-08
Published:2020-09-08
Updated:2021-03-10
Summary:A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
CVSS v3 Severity:4.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
3.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
3.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-25639

Source: CCN
Type: Red Hat Bugzilla – Bug 1876995
(CVE-2020-25639) - CVE-2020-25639 kernel: NULL pointer dereference via nouveau ioctl can lead to DoS

Source: MISC
Type: Exploit, Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1876995

Source: XF
Type: UNKNOWN
linux-kernel-cve202025639-dos(194592)

Source: FEDORA
Type: Third Party Advisory
FEDORA-2021-1db4ab0a3d

Source: FEDORA
Type: Third Party Advisory
FEDORA-2021-a2d3ad5dda

Source: CCN
Type: Nouveau mailing list, Fri Aug 28 09:28:46 UTC 2020
[Nouveau] [PATCH] drm/nouveau: bail out of nouveau_channel_new if channel init fails

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version <= 5.11.2)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:redhat:openshift_container_platform:4.4:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openshift_container_platform:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:messaging_realtime_grid:2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7576
    P
    libblkid-devel-2.37.4-150500.7.16 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7713
    P
    log4j-2.17.2-150200.4.24.13 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:52003
    P
    Security update for libksba (Moderate)
    2023-01-09
    oval:org.opensuse.security:def:665
    P
    Security update for samba (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:93154
    P
    (Important)
    2022-07-12
    oval:org.opensuse.security:def:93307
    P
    (Important)
    2022-07-06
    oval:org.opensuse.security:def:3567
    P
    libXtst6-1.2.2-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3453
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3516
    P
    gtk2-data-2.24.31-9.6.28 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95412
    P
    Security update for rubygem-rack (Critical)
    2022-06-27
    oval:org.opensuse.security:def:95078
    P
    reiserfs-kmp-default-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2960
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94925
    P
    libXcursor1-32bit-1.1.15-1.18 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95083
    P
    kernel-azure-5.14.21-150400.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94590
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95197
    P
    kernel-default-extra-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95028
    P
    kernel-docs-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94628
    P
    libcaca-devel-0.99.beta19.git20171003-150200.11.6.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:89
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:95423
    P
    Security update for MozillaThunderbird (Important)
    2022-06-13
    oval:org.opensuse.security:def:100104
    P
    (Important)
    2022-03-24
    oval:org.opensuse.security:def:101638
    P
    Security update for xerces-j2 (Important)
    2022-02-18
    oval:org.opensuse.security:def:99199
    P
    (Moderate)
    2022-01-20
    oval:org.opensuse.security:def:112507
    P
    kernel-devel-5.14.6-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:102125
    P
    Security update for the Linux Kernel (Important)
    2022-01-11
    oval:org.opensuse.security:def:4516
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP5) (Important)
    2021-11-17
    oval:org.opensuse.security:def:102299
    P
    Security update for the Linux Kernel (Important)
    2021-11-11
    oval:org.opensuse.security:def:102136
    P
    Security update for python (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:5875
    P
    Security update for libvirt (Moderate)
    2021-10-04
    oval:org.opensuse.security:def:105999
    P
    kernel-devel-5.14.6-1.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:5864
    P
    Security update for ghostscript (Critical)
    2021-09-21
    oval:org.opensuse.security:def:63102
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101341
    P
    apache2-mod_apparmor-2.13.6-1.31 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2013
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2036
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1930
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71848
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101277
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72738
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62107
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63019
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1018
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100865
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:99394
    P
    (Important)
    2021-07-12
    oval:org.opensuse.security:def:9843
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:69983
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:8330
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:93001
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:91541
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:9088
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:98836
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:92444
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:99593
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:68102
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:105196
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:91886
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:99004
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:92643
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:10394
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:70534
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:99792
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:7013
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:92054
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:9644
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:69784
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:92842
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:8893
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:98506
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:97227
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:92249
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:20324
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:67816
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:88558
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:59585
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:127213
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:4731
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:125331
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:10198
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:70338
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:89240
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:6727
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:59843
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:33762
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:19571
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:9444
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:69584
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:125648
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:21843
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:8697
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:89498
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:97214
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:34020
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:8263
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:88241
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:126816
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:24015
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:125103
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:102678
    P
    Security update for the Linux Kernel (Important)
    2021-02-10
    oval:org.opensuse.security:def:118435
    P
    Security update for the Linux Kernel (Important)
    2021-02-10
    oval:org.opensuse.security:def:68802
    P
    Security update for the Linux Kernel (Important)
    2021-02-10
    oval:org.opensuse.security:def:109344
    P
    Security update for the Linux Kernel (Important)
    2021-02-10
    oval:org.opensuse.security:def:95965
    P
    Security update for the Linux Kernel (Important)
    2021-02-10
    oval:org.opensuse.security:def:117818
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:109140
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:6459
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:95586
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:97175
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:26157
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:109664
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:108791
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:66953
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:96182
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:61098
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:34580
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:76021
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:20533
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:117888
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:109287
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:8372
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:95761
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:97177
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:102872
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:118634
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:5144
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:108802
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:66964
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:96326
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:35275
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:76032
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:102474
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:118063
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:68284
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:108007
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:64605
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:95908
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:60392
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:102998
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:73727
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:119804
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:19615
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:117521
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:108965
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:67548
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:102621
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:10664
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:70804
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:118373
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:109538
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:68665
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:4283
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:108304
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:7195
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:65605
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:60403
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:34569
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:74673
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:110671
    P
    Security update for the Linux Kernel (Important)
    2021-01-16
    oval:org.opensuse.security:def:111338
    P
    Security update for the Linux Kernel (Important)
    2021-01-14
    BACK
    linux linux kernel *
    fedoraproject fedora 32
    fedoraproject fedora 33
    redhat openshift container platform 4.4
    redhat openshift container platform 4.5
    redhat openshift container platform 4.6
    redhat enterprise linux 5.0
    redhat enterprise linux 6.0
    redhat enterprise linux 7.0
    redhat enterprise linux 8.0
    redhat messaging realtime grid 2.0