5.5

CVE-2020-14314

A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 5.8.9
Linux ≫ Linux Kernel Version 5.9.0 Update rc1
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build12533 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build12658 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build12859 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build13170 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build13586 SwPlatform vsphere
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build13861 SwPlatform vsphere
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.275
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://usn.ubuntu.com/4578-1/
Third Party Advisory
https://usn.ubuntu.com/4579-1/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4576-1/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14314
Third Party Advisory
Issue Tracking
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5872331b3d91820e14716632ebb56b1399b34fe1
Patch
Vendor Advisory
https://lore.kernel.org/linux-ext4/f53e246b-647c-64bb-16ec-135383c70ad7%40redhat.com/T/#u
https://www.starwindsoftware.com/security/sw-20210325-0003/
Third Party Advisory