Buffer overflow in Intel products - CVE-2020-12321

 

Buffer overflow in Intel products - CVE-2020-12321

Published: November 12, 2020 / Updated: November 16, 2020


Vulnerability identifier: #VU48422
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12321
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a boundary error. A remote attacker on the local network can trigger memory corruption and execute arbitrary code on the target system with elevated privileges.


Affected software

Intel Wireless Bluetooth
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Wireless-AC 9462
Intel Wireless-AC 9461
Intel Wireless-AC 9260
Intel Dual Band Wireless-AC 8265
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 3168
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3165
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
linux-firmware (Red Hat package)
linux-firmware
IBM Security Guardium
OpenShift Virtualization
Data Computing Appliance (DCA)
Dell EMC Storage Monitoring and Reporting (SMR)
Session Smart Router
Juniper Junos Space

How to mitigate CVE-2020-12321

Install updates from vendor's website.

Intel Wireless Bluetooth - update to 21.110
linux-firmware (Red Hat package) - addressed in versions 20190429-73.gitddde598.el7_7, 20190516-96.git711d3297.el8_1, 20191202-99.gite8a0f4c9.el8_2, 20200421-80.git78c0348.el7_9, 20200619-101.git3890db36.el8_3
OpenShift Virtualization - update to 2.5.3
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
Juniper Junos Space - update to 22.2R1
linux-firmware - update to 20211027-1

External References

Related Security Bulletins