CVE-2020-25643: Debian Linux

High severity, CVSS 7.2. EPSS: 3.3% chance of exploitation in the next 30 days.

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Linux Linux Kernel: from 2.6.29, before 4.4.238 (fixed in 4.4.238); from 4.5, before 4.9.238 (fixed in 4.9.238); from 4.10, before 4.14.200 (fixed in 4.14.200); from 4.15, before 4.19.148 (fixed in 4.19.148); from 4.20, before 5.4.68 (fixed in 5.4.68); from 5.5, before 5.8.12 (fixed in 5.8.12); …
  • Netapp h410c Firmware: affected versions not specified
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Starwindsoftware Starwind Virtual San: version v8 only

Published 2020-10-06. Last modified 2026-06-17.