First published: Mon Oct 19 2020(Updated: )
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Elastic Storage Server | >=6.0.0.0<=6.0.1.0 | |
IBM Spectrum Scale | >4.2.0.0<=4.2.3.23 | |
IBM Spectrum Scale | >5.0.0.0<=5.0.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4756 is medium.
CVE-2020-4756 could allow a local attacker to crash the kernel and cause a denial of service in IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2, as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0.
The affected software for CVE-2020-4756 includes IBM Spectrum Scale versions V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2, as well as IBM Elastic Storage System versions 6.0.0 through 6.0.1.0.
A local attacker could invoke a subset of ioctls on the device with invalid arguments, causing a crash in the kernel and resulting in a denial of service.
More information about CVE-2020-4756 can be found at the following links: - IBM X-Force Exchange: [https://exchange.xforce.ibmcloud.com/vulnerabilities/188599](https://exchange.xforce.ibmcloud.com/vulnerabilities/188599) - IBM Support: [https://www.ibm.com/support/pages/node/6349469](https://www.ibm.com/support/pages/node/6349469) - IBM Support: [https://www.ibm.com/support/pages/node/6349475](https://www.ibm.com/support/pages/node/6349475)