← Zuruck zu CVEs
CVE-2020-25284
MEDIUM4.1
Beschreibung
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.
CVE Details
CVSS v3.1 Bewertung4.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorLOCAL
KomplexitatHIGH
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht9/13/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
debian:debian_linuxlinux:linux_kernelopensuse:leap
Schwachen (CWE)
CWE-863
Referenzen
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f44d04e696feaf13d192d942c4f14ad2e117065a(cve@mitre.org)
https://twitter.com/grsecurity/status/1304537507560919041(cve@mitre.org)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html(af854a3a-2127-422b-91ae-364da2661108)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f44d04e696feaf13d192d942c4f14ad2e117065a(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/grsecurity/status/1304537507560919041(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.