CVE-2020-10711: Canonical Ubuntu Linux
Medium severity, CVSS 5.9. EPSS: 3.1% chance of exploitation in the next 30 days.
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Linux Linux Kernel: before 5.7 (fixed in 5.7)
- Opensuse Leap: version 15.1 only; version 15.2 only
- Red Hat 3scale: version 2.0 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only
- Red Hat Enterprise Linux Aus: version 7.4 only
- Red Hat Enterprise Linux Server Tus: version 7.4 only
- Red Hat Messaging Realtime Grid: version 2.0 only
- Red Hat Openstack: version 13 only
- Red Hat Virtualization Host: version 4.0 only
Published 2020-05-22. Last modified 2026-06-17.