7.8

CVE-2020-8835

Exploit

Linux kernel bpf verifier vulnerability

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.4.7 < 5.4.29
Linux ≫ Linux Kernel Version >= 5.5.0 < 5.5.14
Linux ≫ Linux Kernel Version >= 5.6 < 5.6.1
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Netapp ≫ Cloud Backup Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ A700s Firmware Version -
   Netapp ≫ A700s Version -
Netapp ≫ 8300 Firmware Version -
   Netapp ≫ 8300 Version -
Netapp ≫ 8700 Firmware Version -
   Netapp ≫ 8700 Version -
Netapp ≫ A400 Firmware Version -
   Netapp ≫ A400 Version -
Netapp ≫ A320 Firmware Version -
   Netapp ≫ A320 Version -
Netapp ≫ C190 Firmware Version -
   Netapp ≫ C190 Version -
Netapp ≫ A220 Firmware Version -
   Netapp ≫ A220 Version -
Netapp ≫ Fas2720 Firmware Version -
   Netapp ≫ Fas2720 Version -
Netapp ≫ Fas2750 Firmware Version -
   Netapp ≫ Fas2750 Version -
Netapp ≫ A800 Firmware Version -
   Netapp ≫ A800 Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H610c Firmware Version -
   Netapp ≫ H610c Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ H615c Firmware Version -
   Netapp ≫ H615c Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.01% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Canonical 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TF4PQZBEPNXDSK5DOBMW54OCLP25FTCD/
http://www.openwall.com/lists/oss-security/2021/07/20/1
Third Party Advisory
Exploit
Mailing List
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git/commit/?id=f2d67fec0b43edce8c416101cdc52e71145b5fef
Patch
Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f2d67fec0b43edce8c416101cdc52e71145b5fef
Patch
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7OONYGMSYBEFHLHZJK3GOI5Z553G4LD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXBWSHZ6DJIZVXKXGZPK6QPFCY7VKZEG/
https://lore.kernel.org/bpf/20200330160324.15259-1-daniel%40iogearbox.net/T/
https://security.netapp.com/advisory/ntap-20200430-0004/
Third Party Advisory
https://usn.ubuntu.com/4313-1/
Third Party Advisory
https://usn.ubuntu.com/usn/usn-4313-1
Third Party Advisory
https://www.openwall.com/lists/oss-security/2020/03/30/3
Patch
Third Party Advisory
Mailing List
https://www.thezdi.com/blog/2020/3/19/pwn2own-2020-day-one-results
Third Party Advisory