CVE-2020-25643: Debian Linux
High severity, CVSS 7.2. EPSS: 3.3% chance of exploitation in the next 30 days.
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Linux Linux Kernel: from 2.6.29, before 4.4.238 (fixed in 4.4.238); from 4.5, before 4.9.238 (fixed in 4.9.238); from 4.10, before 4.14.200 (fixed in 4.14.200); from 4.15, before 4.19.148 (fixed in 4.19.148); from 4.20, before 5.4.68 (fixed in 5.4.68); from 5.5, before 5.8.12 (fixed in 5.8.12); …
- Netapp h410c Firmware: affected versions not specified
- Opensuse Leap: version 15.1 only; version 15.2 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Starwindsoftware Starwind Virtual San: version v8 only
Published 2020-10-06. Last modified 2026-06-17.