CVE-2020-12465
Linux Kernel vulnerability analysis and mitigation

Overview

An array overflow vulnerability was discovered in mt76_add_fragment function in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before version 5.5.10 (also known as CID-b102f0c522cf). The vulnerability was disclosed on April 29, 2020 (NVD).

Technical details

The vulnerability occurs when the hardware receives an oversized packet with too many rx fragments, causing skb_shinfo(skb)->frags to overflow and corrupt memory of adjacent pages. This becomes particularly problematic if it corrupts the freelist pointer of a slab page. The issue was fixed by adding a check to ensure the number of fragments doesn't exceed the array size before adding new fragments (Linux Commit). The vulnerability has a CVSS v3.1 Base Score of 6.7 MEDIUM (Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) (NVD).

Impact

Successful exploitation of this vulnerability could lead to memory corruption, potentially resulting in system crashes or arbitrary code execution. The vulnerability affects the system's memory management, particularly when handling network packets with multiple fragments (NetApp Advisory).

Exploitability

The vulnerability requires local access and high privileges to exploit. The attack complexity is low, but no user interaction is needed once the attacker has the necessary access. The vulnerability has been assigned CWE-120 (Buffer Copy without Checking Size of Input) classification (NVD).

Mitigation and workarounds

The primary mitigation is to update the Linux kernel to version 5.5.10 or later, which contains the fix. The patch adds a boundary check before adding new fragments to prevent the overflow condition (Linux Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64597CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-5.4
NoYesAug 06, 2026
CVE-2026-68480HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules-partner
NoYesAug 06, 2026
CVE-2026-64598HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.8
NoYesAug 06, 2026
CVE-2026-64604HIGH7.7
  • Linux Kernel logoLinux Kernel
  • linux-riscv-5.15
NoYesAug 06, 2026
CVE-2026-64603NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg-5.15
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management