Buffer overflow in Intel products - CVE-2020-12321
Published: November 12, 2020 / Updated: November 16, 2020
Vulnerability identifier: #VU48422
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12321
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to a boundary error. A remote attacker on the local network can trigger memory corruption and execute arbitrary code on the target system with elevated privileges.
Affected software
Intel Wireless Bluetooth
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Wireless-AC 9462
Intel Wireless-AC 9461
Intel Wireless-AC 9260
Intel Dual Band Wireless-AC 8265
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 3168
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3165
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
linux-firmware (Red Hat package)
linux-firmware
IBM Security Guardium
OpenShift Virtualization
Data Computing Appliance (DCA)
Dell EMC Storage Monitoring and Reporting (SMR)
Session Smart Router
Juniper Junos Space
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Wireless-AC 9462
Intel Wireless-AC 9461
Intel Wireless-AC 9260
Intel Dual Band Wireless-AC 8265
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 3168
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3165
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
linux-firmware (Red Hat package)
linux-firmware
IBM Security Guardium
OpenShift Virtualization
Data Computing Appliance (DCA)
Dell EMC Storage Monitoring and Reporting (SMR)
Session Smart Router
Juniper Junos Space
How to mitigate CVE-2020-12321
Install updates from vendor's website.
Intel Wireless Bluetooth - update to 21.110
linux-firmware (Red Hat package) - addressed in versions 20190429-73.gitddde598.el7_7, 20190516-96.git711d3297.el8_1, 20191202-99.gite8a0f4c9.el8_2, 20200421-80.git78c0348.el7_9, 20200619-101.git3890db36.el8_3
OpenShift Virtualization - update to 2.5.3
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
Juniper Junos Space - update to 22.2R1
linux-firmware - update to 20211027-1
linux-firmware (Red Hat package) - addressed in versions 20190429-73.gitddde598.el7_7, 20190516-96.git711d3297.el8_1, 20191202-99.gite8a0f4c9.el8_2, 20200421-80.git78c0348.el7_9, 20200619-101.git3890db36.el8_3
OpenShift Virtualization - update to 2.5.3
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
Juniper Junos Space - update to 22.2R1
linux-firmware - update to 20211027-1
External References
Related Security Bulletins
- Multipel vulnerabilities in Intel Wireless Bluetooth products
- Red Hat Enterprise Linux 8 update for linux-firmware
- Red Hat Enterprise Linux 8.1 update for linux-firmware
- Red Hat Enterprise Linux 7 update for linux-firmware
- CentOS 7 update for linux-firmware
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Red Hat Enterprise Linux 7 update for linux-firmware
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 8.2 Extended Update Support update for linux-firmware
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- openEuler update for linux-firmware
- Multiple vulnerabilities in OpenShift Virtualization 2.5
- Juniper Session Smart Router update for third-party components