4.7
CVSSv3

CVE-2020-27170

Published: 20/03/2021 Updated: 07/11/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in the Linux kernel prior to 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 14.04

canonical ubuntu linux 20.04

debian debian linux 9.0

Vendor Advisories

A flaw was found in the Linux kernel Speculation on pointer arithmetic against bpf_context pointer allows unprivileged local users to leak content of kernel memory The highest threat from this vulnerability is to data confidentiality ...
A gap in the Linux kernel mechanism to mitigate speculatively out-of-bounds loads (Spectre mitigation) has been identified Unprivileged BPF programs running on affected systems can bypass the protection and execute speculatively out-of-bounds loads from any location within the kernel memory This can be abused to extract contents of kernel memory ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Re: CVE-2021-20219 Linux kernel: improper synchronization in flush_to_ldisc() can lead to DoS <!--X-Subject-Header-End--> ...

Github Repositories

Get a Ubuntu package changelog from the command line

ubuntu-package-changelog ubuntu-package-changelog can be used to get a changelog for a given Ubuntu source package Eg: ubuntu-package-changelog focal Updates linux-azure linux-azure (540-104345) focal; urgency=medium [ Ubuntu: 540-7078 ] * CVE-2020-27170 - bpf: Fix off-by-one for area size in creating mask to left * CVE-2020-27171 - bpf: Prohibit alu ops

Recent Articles

Newly-Discovered Vulnerabilities Could Allow for Bypass of Spectre Mitigations in Linux
Symantec Threat Intelligence Blog • Threat Hunter Team • 29 Mar 2024

Bugs could allow a malicious user to access data belonging to other users.

Posted: 29 Mar, 20215 Min ReadThreat Intelligence SubscribeNewly-Discovered Vulnerabilities Could Allow for Bypass of Spectre Mitigations in LinuxBugs could allow a malicious user to access data belonging to other users.Two new vulnerabilities have been patched in the Linux kernel which, if exploited, could bypass existing mitigations for the Spectre vulnerabilities. The vulnerabilities were discovered by Piotr Krysiuk, a researcher on Symantec’s Threa...