Vulnerability Description
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | All versions |
| Debian | Debian Linux | 9.0 |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H300E Firmware | - |
| Netapp | H300E | - |
| Netapp | H500E Firmware | - |
| Netapp | H500E | - |
| Netapp | H700E Firmware | - |
| Netapp | H700E | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
| Netapp | H410C Firmware | - |
| Netapp | H410C | - |
| Netapp | Aff A250 Firmware | - |
| Netapp | Aff A250 | - |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2020/11/30/5ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/12/28/1ExploitMailing ListPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1897668%2CIssue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c6PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00018.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210702-0004/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4843Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/11/30/5%2CMailing List
- https://www.openwall.com/lists/oss-security/2020/12/28/1%2CMailing List
- http://www.openwall.com/lists/oss-security/2020/11/30/5ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/12/28/1ExploitMailing ListPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1897668%2CIssue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c6PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00018.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2020-27815?
CVE-2020-27815 is a vulnerability with a CVSS score of 7.8 (HIGH). A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating p...
How severe is CVE-2020-27815?
CVE-2020-27815 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27815?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Netapp H300S Firmware, Netapp H300S, Netapp H500S Firmware.