Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-27815


A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.


Published

2021-05-26T13:15:07.647

Last Modified

2024-11-21T05:21:51.940

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

8.5

Weaknesses
  • Type: Primary
    CWE-119
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel > 4.4.249 Yes
Operating System linux linux_kernel < 4.9.249 Yes
Operating System linux linux_kernel < 4.14.213 Yes
Operating System linux linux_kernel < 4.19.164 Yes
Operating System linux linux_kernel < 5.4.86 Yes
Operating System linux linux_kernel < 5.10.4 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp h300e_firmware - Yes
Hardware netapp h300e - No
Operating System netapp h500e_firmware - Yes
Hardware netapp h500e - No
Operating System netapp h700e_firmware - Yes
Hardware netapp h700e - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No
Operating System netapp h410c_firmware - Yes
Hardware netapp h410c - No
Operating System netapp aff_a250_firmware - Yes
Hardware netapp aff_a250 - No
Operating System netapp fas500f_firmware - Yes
Hardware netapp fas500f - No

References