CVE-2020-15780: Medium severity Linux Linux kernel vulnerability
A flaw was found in how the ACPI table loading through acpiconfigfs was handled when the kernel was locked down. This flaw allows a (root) privileged local user to circumvent the kernel lockdown restrictions. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A flaw was found in the way ACPI table loading through acpiconfigfs was handled when the kernel was locked down. A (root) privileged local user could use this flaw to circumvent the kernel lockdown restrictions.
— Red Hat
An issue was discovered in drivers/acpi/acpiconfigfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.14.3.rt13.67.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.14.3.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-80.27.2.el8_0 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.24.2.el8_1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-15780?
CVE-2020-15780 has a high severity rating, primarily affecting data confidentiality and integrity.
How do I fix CVE-2020-15780?
To mitigate CVE-2020-15780, update your kernel to the remedied versions provided by your Linux distribution.
What are the affected systems for CVE-2020-15780?
CVE-2020-15780 affects several Linux kernel versions including Red Hat, OpenSUSE, and Ubuntu systems.
Who is at risk with CVE-2020-15780?
Local users with root privileges are at risk of circumventing kernel lockdown restrictions due to CVE-2020-15780.
Is there a workaround for CVE-2020-15780?
There are no known workarounds for CVE-2020-15780; the best option is to upgrade to secure kernel versions.