CVE-2020-25284Incorrect Authorization in Kernel

Severity
4.1MEDIUMNVD
EPSS
0.1%
top 77.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateMay 24

Description

The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 0.5 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel< 5.8.9
Debianlinux/linux_kernel< 5.8.10-1+3
NVDopensuse/leap15.1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5f3v-3wp6-f5wm: The rbd block device driver in drivers/block/rbd2022-05-24
OSV
CVE-2020-25284: The rbd block device driver in drivers/block/rbd2020-09-13
CVEList
CVE-2020-25284: The rbd block device driver in drivers/block/rbd2020-09-13

📋Vendor Advisories

7
Ubuntu
Linux kernel (OEM) vulnerabilities2021-02-25
Ubuntu
Linux kernel vulnerabilities2020-12-03
Ubuntu
Linux kernel vulnerabilities2020-12-03
Ubuntu
Linux kernel vulnerabilities2020-12-02
Red Hat
kernel: incomplete permission checking for access to rbd devices2020-09-13

💬Community

2
Bugzilla
CVE-2020-25284 kernel: incomplete permission checking for access to rbd devices [fedora-all]2020-09-25
Bugzilla
CVE-2020-25284 kernel: incomplete permission checking for access to rbd devices2020-09-25
CVE-2020-25284 — Incorrect Authorization in Kernel | cvebase