MEDIUM 5.5 Microsoft
CVE-2020-26088
A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets bypassing security mechanisms aka CID-26896f01467a.
Microsoft Security Update 2020-Sep: A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets bypassing security mechanisms aka CID-26896f01467a.
Affected Products
- cm1 kernel 5.4.91-3 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-26088
- https://nvd.nist.gov/vuln/detail/CVE-2020-26088
This medium severity vulnerability with a CVSS score of 5.5 was published on 2020-09-08 via Microsoft. Affected: cm1 kernel 5.4.91-3 on CBL Mariner 1.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.