CVE-2020-1749
Publication date 4 March 2020
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted link; rather sending the data unencrypted. This would allow anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
From the Ubuntu Security Team
Xiumei Mu discovered that the IPSec implementation in the Linux kernel did not properly encrypt IPv6 traffic in some situations. An attacker could use this to expose sensitive information.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Fixed 4.15.0-106.107
|
|
16.04 LTS xenial |
Fixed 4.4.0-184.214
|
|
14.04 LTS trusty | Ignored | |
linux-aws | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Fixed 4.15.0-1073.77
|
|
16.04 LTS xenial |
Fixed 4.4.0-1109.120
|
|
14.04 LTS trusty |
Fixed 4.4.0-1073.77
|
|
linux-aws-5.0 | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-aws-5.3 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-aws-hwe | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial |
Fixed 4.15.0-1073.77~16.04.1
|
|
14.04 LTS trusty | Not in release | |
linux-azure | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic | Ignored | |
16.04 LTS xenial |
Fixed 4.15.0-1089.99~16.04.1
|
|
14.04 LTS trusty |
Fixed 4.15.0-1089.99~14.04.1
|
|
linux-azure-4.15 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 4.15.0-1089.99
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-azure-5.3 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.3.0-1013.14~18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-azure-edge | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-gcp | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic | Ignored | |
16.04 LTS xenial |
Fixed 4.15.0-1077.87~16.04.1
|
|
14.04 LTS trusty | Not in release | |
linux-gcp-4.15 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 4.15.0-1077.87
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-gcp-5.3 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.3.0-1012.13~18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-gcp-edge | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-gke-4.15 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 4.15.0-1063.66
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-gke-5.0 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.0.0-1042.43
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-gke-5.3 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.3.0-1012.13~18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-hwe | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.3.0-40.32~18.04.1
|
|
16.04 LTS xenial |
Fixed 4.15.0-106.107~16.04.1
|
|
14.04 LTS trusty | Not in release | |
linux-hwe-edge | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Not in release | |
linux-kvm | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Fixed 4.15.0-1067.68
|
|
16.04 LTS xenial |
Fixed 4.4.0-1075.82
|
|
14.04 LTS trusty | Not in release | |
linux-lts-trusty | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-lts-xenial | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Fixed 4.4.0-184.214~14.04.1
|
|
linux-oem | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 4.15.0-1087.97
|
|
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Not in release | |
linux-oem-5.6 | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-oem-osp1 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.0.0-1059.64
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-oracle | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Fixed 4.15.0-1045.49
|
|
16.04 LTS xenial |
Fixed 4.15.0-1045.49~16.04.1
|
|
14.04 LTS trusty | Not in release | |
linux-oracle-5.0 | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-oracle-5.3 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-raspi | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-raspi2 | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Fixed 4.15.0-1063.67
|
|
16.04 LTS xenial |
Fixed 4.4.0-1134.143
|
|
14.04 LTS trusty | Not in release | |
linux-raspi2-5.3 | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 5.3.0-1018.20~18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-riscv | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
linux-snapdragon | 20.04 LTS focal | Not in release |
18.04 LTS bionic |
Fixed 4.15.0-1080.87
|
|
16.04 LTS xenial |
Fixed 4.4.0-1138.146
|
|
14.04 LTS trusty | Not in release |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-4391-1
- Linux kernel vulnerabilities
- 11 June 2020
- USN-4390-1
- Linux kernel vulnerabilities
- 11 June 2020
- USN-4388-1
- Linux kernel vulnerabilities
- 9 June 2020