CVE-2020-25645 is a confidentiality flaw in the Linux kernel (versions prior to 5.9-rc7) affecting products like Canonical, Debian, and openSUSE. It allows unencrypted traffic between Geneve endpoints, even when IPsec is configured, enabling an attacker to intercept sensitive data. Rated High (CVSS 7.5), this vulnerability requires no user interaction or special privileges, posing a significant risk to data confidentiality. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.9.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.9.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.9.0:-:*:*:*:*:*:* | ||
5.9.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.9.0:rc1:*:*:*:*:*:* | ||
5.9.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.9.0:rc2:*:*:*:*:*:* | ||
5.9.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.9.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
Oct 13, 2020kernel: Geneve/IPsec traffic may be unencrypted between two Geneve endpoints
Sep 16, 2020