CVE-2020-14385

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service. The highest threat from this vulnerability is to system availability.

References

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14385

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f4020438fab05364018c91f7e02ebdd192085933

https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html

https://usn.ubuntu.com/4576-1/

Details

Source: MITRE

Published: 2020-09-15

Updated: 2020-10-15

Type: CWE-131

Risk Information

CVSS v2

Base Score: 4.7

Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (26 total)

IDNameProductFamilySeverity
147690EulerOS Virtualization 2.9.0 : kernel (EulerOS-SA-2021-1642)NessusHuawei Local Security Checks
high
147512EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-1604)NessusHuawei Local Security Checks
high
147345NewStart CGSL MAIN 6.02 : kernel Multiple Vulnerabilities (NS-SA-2021-0051)NessusNewStart CGSL Local Security Checks
high
146282openSUSE Security Update : RT kernel (openSUSE-2021-242)NessusSuSE Local Security Checks
high
145986CentOS 8 : kernel (CESA-2020:4286)NessusCentOS Local Security Checks
high
144731EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2021-1039)NessusHuawei Local Security Checks
high
144549CentOS 7 : kernel (CESA-2020:5437)NessusCentOS Local Security Checks
high
144404RHEL 7 : kernel (RHSA-2020:5437)NessusRed Hat Local Security Checks
high
144402RHEL 7 : kernel-rt (RHSA-2020:5441)NessusRed Hat Local Security Checks
high
144333Oracle Linux 7 : kernel (ELSA-2020-5437)NessusOracle Linux Local Security Checks
high
144295Scientific Linux Security Update : kernel on SL7.x x86_64 (2020:5437)NessusScientific Linux Local Security Checks
high
143671SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:2879-1)NessusSuSE Local Security Checks
medium
143236RHEL 8 : kernel (RHSA-2020:5199)NessusRed Hat Local Security Checks
high
141777Oracle Linux 8 : kernel (ELSA-2020-4286)NessusOracle Linux Local Security Checks
high
141606RHEL 8 : kernel (RHSA-2020:4286)NessusRed Hat Local Security Checks
high
141603RHEL 8 : kernel-rt (RHSA-2020:4289)NessusRed Hat Local Security Checks
high
141580RHEL 8 : kernel (RHSA-2020:4287)NessusRed Hat Local Security Checks
high
141451Ubuntu 18.04 LTS / 20.04 LTS : Linux kernel vulnerabilities (USN-4576-1)NessusUbuntu Local Security Checks
high
141395Oracle Linux 8 : Unbreakable Enterprise kernel (ELSA-2020-5884)NessusOracle Linux Local Security Checks
high
141332EulerOS 2.0 SP9 : kernel (EulerOS-SA-2020-2166)NessusHuawei Local Security Checks
high
141329EulerOS 2.0 SP9 : kernel (EulerOS-SA-2020-2176)NessusHuawei Local Security Checks
high
141161openSUSE Security Update : the Linux Kernel (openSUSE-2020-1586)NessusSuSE Local Security Checks
medium
140999EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-2151)NessusHuawei Local Security Checks
high
140959EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-2011)NessusHuawei Local Security Checks
medium
140933Debian DLA-2385-1 : linux-4.19 security updateNessusDebian Local Security Checks
high
140305Fedora 32 : kernel / kernel-headers / kernel-tools (2020-708b23f2ce)NessusFedora Local Security Checks
medium