CVE-2020-11900
Description
The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A double-free vulnerability in the IPv4 tunneling code of the Treck TCP/IP stack (before 6.0.1.41) allows a remote, unauthenticated attacker to potentially cause denial of service or arbitrary code execution.
Vulnerability
CVE-2020-11900 is a double-free vulnerability in the IPv4 tunneling code of the Treck TCP/IP stack, affecting versions prior to 6.0.1.41 [1][2]. The bug exists in the memory handling routines for IPv4 tunnel packets and can be triggered when the stack processes specially-crafted network packets [1][2]. This vulnerability is part of the Ripple20 set of memory management bugs in the Treck stack [2].
Exploitation
An attacker can exploit this vulnerability by sending a specially-crafted IPv4 packet to a target device using an affected version of the Treck TCP/IP stack [1][2]. The attacker does not need any authentication or prior access, and the attack is performed over the network [2]. The crafted packet triggers a double-free condition in the tunnel processing code, leading to memory corruption [1].
Impact
Successful exploitation of this double-free vulnerability may allow a remote, unauthenticated attacker to achieve a range of impacts, including denial of service (DoS), information disclosure, or arbitrary code execution [2]. The exact impact depends on the implementation and surrounding system details [2]. Given the widespread use of the Treck stack in embedded systems (industrial control, medical devices, etc.), the consequences can be severe [2].
Mitigation
Treck released a fix in version 6.0.1.67 or later; contact Treck at security@treck.com for updates [2]. Downstream users should contact their embedded system vendor for patched firmware [2]. Intel also published mitigation guidance in INTEL-SA-00295 [1]. Dell has released updates for certain client platforms and Teradici firmware [4]. As of June 2020, CVE-2020-11900 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Treck/TCP/IP stackdescription
- Range: <6.0.1.41
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyCmitrevendor-advisoryx_refsource_CISCO
- www.kb.cert.org/vuls/id/257161mitrethird-party-advisoryx_refsource_CERT-VN
- www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-006.txtmitrex_refsource_CONFIRM
- jsof-tech.com/vulnerability-disclosure-policy/mitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20200625-0006/mitrex_refsource_CONFIRM
- support.hpe.com/hpesc/public/docDisplaymitrex_refsource_MISC
- www.dell.com/support/article/de-de/sln321836/dell-response-to-the-ripple20-vulnerabilitiesmitrex_refsource_MISC
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlmitrex_refsource_CONFIRM
- www.jsof-tech.com/ripple20/mitrex_refsource_MISC
- www.kb.cert.org/vuls/id/257161/mitrex_refsource_MISC
- www.treck.commitrex_refsource_MISC
News mentions
0No linked articles in our index yet.