First published: Wed May 26 2021(Updated: )
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >4.4.249 | |
Linux Kernel | >=4.5<4.9.249 | |
Linux Kernel | >=4.10<4.14.213 | |
Linux Kernel | >=4.15<4.19.164 | |
Linux Kernel | >=4.20<5.4.86 | |
Linux Kernel | >=5.5<5.10.4 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700E | ||
NetApp H700E | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
NetApp A250 Firmware | ||
NetApp A250 Firmware | ||
NetApp FAS 500F Firmware | ||
NetApp FAS500F Firmware | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
All of | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700E | ||
NetApp H700E | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
All of | ||
NetApp A250 Firmware | ||
NetApp A250 Firmware | ||
All of | ||
NetApp FAS 500F Firmware | ||
NetApp FAS500F Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.133-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27815 has a high severity due to its potential to cause system panics and memory corruption.
To fix CVE-2020-27815, upgrade to the recommended Linux kernel versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
CVE-2020-27815 affects local users with the ability to set extended attributes on systems running specific vulnerable versions of the Linux kernel.
Yes, CVE-2020-27815 can potentially allow local attackers to escalate their privileges on the affected system.
An attacker exploiting CVE-2020-27815 can cause a system panic, leading to denial of service and possible memory corruption.