CVE-2020-25645: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Linux Linux Kernel: before 5.9.0 (fixed in 5.9.0); version 5.9.0 only
  • Netapp Hci Compute Node BIOS: affected versions not specified
  • Netapp Solidfire & Hci Management Node: affected versions not specified
  • Netapp Solidfire & Hci Storage Node: affected versions not specified
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-10-13. Last modified 2026-06-17.