A missing CAPNETRAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
[
{
"target": {
"file": "net/nfc/rawsock.c"
},
"id": "CVE-2020-26088-9ef66833",
"deprecated": false,
"digest": {
"line_hashes": [
"56028584218632220880980935605668195958",
"231892684048679820802847841268397316234",
"298951847556439549836405212819625889768",
"101152459818646555585578730582864193463",
"320643792955621866137020404385496535780",
"158265123157267600573412033859330069279",
"16840148217231940989984489741212714498"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/torvalds/linux/commit/26896f01467a28651f7a536143fe5ac8449d4041",
"signature_version": "v1"
},
{
"target": {
"function": "rawsock_create",
"file": "net/nfc/rawsock.c"
},
"id": "CVE-2020-26088-c441ec5c",
"deprecated": false,
"digest": {
"length": 791.0,
"function_hash": "157224914794030181340391866579283977221"
},
"signature_type": "Function",
"source": "https://github.com/torvalds/linux/commit/26896f01467a28651f7a536143fe5ac8449d4041",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-26088.json"