Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-12465

19
FAUCET Score

CVE-2020-12465 describes an array overflow vulnerability in the mt76_add_fragment function within the MediaTek wireless driver (mt76) of the Linux kernel prior to version 5.5.10. This flaw allows an oversized packet with excessive rx fragments to corrupt adjacent memory, affecting Linux and NetApp products. Rated as MEDIUM severity with a CVSS score of 6.7, the vulnerability requires high privileges (PR:H) and local access (AV:L) to achieve high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.16, < 4.19.111CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.26CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.5.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.7MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 79th percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17036-16820Fixed in: 5.4.91-3
microsoftpatch availablevia msrc
Product: cm1 kernel 5.4.91-3 on CBL Mariner 1.0Fixed in: 5.4.91-3
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 5.4.91-3
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 5.4.91-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-240.el8
View patch

Vendor Advisories (3)

microsoft2020-Sep/CVE-2020-12465

CVE-2020-12465

Sep 8, 2020
microsoft2020-Apr/CVE-2020-12465Moderate

An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10 aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.

Apr 14, 2020
redhatCVE-2020-12465Moderate

kernel: buffer overflow in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c

Mar 3, 2020

References

cdn.kernel.org / pub/linux/kernel/v5.x/ChangeLog-5.5.10
Release NotesVendor Advisory
github.com / torvalds/linux/commit/b102f0c522cf668c8382c56a4f771b37d011cda2
PatchThird Party Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
security.netapp.com / advisory/ntap-20200608-0001
Third Party Advisory