Out-of-bounds read in uIP and Contiki OS - CVE-2020-13987
Published: December 29, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
A remote attacker can send specially crafted traffic to the system, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
Contiki OS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
Ubuntu
open-iscsi (Ubuntu package)
iscsiuio
iscsiuio-debuginfo
libopeniscsiusr0_2_0
libopeniscsiusr0_2_0-debuginfo
open-iscsi
open-iscsi-debuginfo
open-iscsi-debugsource
open-iscsi-devel
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2020-13987
iscsiuio - addressed in versions 0.7.8.2-12.27.2, 0.7.8.2-13.42.1, 0.7.8.2-53.34.1
iscsiuio-debuginfo - addressed in versions 0.7.8.2-12.27.2, 0.7.8.2-13.42.1, 0.7.8.2-53.34.1
libopeniscsiusr0_2_0 - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
libopeniscsiusr0_2_0-debuginfo - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-debuginfo - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-debugsource - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-devel - update to 2.0.876-13.42.1
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007