CVE-2020-27194
published 2020-10-16CVE-2020-27194: An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
2.02%
79.0th percentile
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.9.1-1 (bookworm) | linux 5.9.1-1 (bookworm) |
| linux | linux_kernel | < 5.8.15 | 5.8.15 |
| linux | linux_kernel | >= 0 < 5.9.1-1 | 5.9.1-1 |
| linux | linux_kernel | >= 0 < 5.9.1-1 | 5.9.1-1 |
| linux | linux_kernel | >= 0 < 5.9.1-1 | 5.9.1-1 |
| linux | linux_kernel | >= 0 < 5.9.1-1 | 5.9.1-1 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-11-11·CVSS 5.5
CVE-2020-8694 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Simon Scannell discovered that the bpf verifier in the Linux kernel did not
properly calculate register bounds for certain operations. A local attacker
could use this to expose sensitive information (kernel memory) or gain
administrative privileges. (CVE-2020-27194)
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) driver in the Linux kernel did not properly
restrict access to power data. A local attacker could possibly use this to
expose sensitive information. (CVE-2020-8694)
Instructions: After a standard system update you need to reboot your computer to make
all
Microsoft
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values aka CID-5b9fbeb75b6a.
vendor_msrc·2020-10-13·CVSS 5.5
CVE-2020-27194 [MEDIUM] CWE-681 An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values aka CID-5b9fbeb75b6a.
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values aka CID-5b9fbeb75b6a.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this
Red Hat
kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c
vendor_redhat·2020-10-08·CVSS 5.5
CVE-2020-27194 [MEDIUM] CWE-190 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c
kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
An out-of-bounds access flaw was found in the Linux kernel’s implementation of the eBPF (Berkeley Packet Filter) code verifier, where an incorrect register bounds calculation occurs while in use of 64-bit values with scalar32_min_max_or (that is BPF_OR). This flaw allows an unprivileged local user (until param kernel.unprivileged_bpf_disabled is set) to have arbitrary read/write access to the kernel memory or escalate their privileges on the system.
Statement: This flaw is rated as having a Mode
Debian
CVE-2020-27194: linux - An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or i...
vendor_debian·2020·CVSS 5.5
CVE-2020-27194 [MEDIUM] CVE-2020-27194: linux - An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or i...
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
Scope: local
bookworm: resolved (fixed in 5.9.1-1)
bullseye: resolved (fixed in 5.9.1-1)
forky: resolved (fixed in 5.9.1-1)
sid: resolved (fixed in 5.9.1-1)
trixie: resolved (fixed in 5.9.1-1)
GHSA
GHSA-r8fj-347g-p44m: An issue was discovered in the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2020-27194 [MEDIUM] CWE-119 GHSA-r8fj-347g-p44m: An issue was discovered in the Linux kernel before 5
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
OSV
CVE-2020-27194: An issue was discovered in the Linux kernel before 5
osv·2020-10-16·CVSS 5.5
CVE-2020-27194 [MEDIUM] CVE-2020-27194: An issue was discovered in the Linux kernel before 5
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
No detection rules found.
No public exploits indexed.
HackerOne
[CVE-2020-27194] Linux kernel: eBPF verifier bug in `or` binary operation tracking function leads to LPE
hackerone·2021-07-23·CVSS 5.5
CVE-2020-27194 [MEDIUM] [CVE-2020-27194] Linux kernel: eBPF verifier bug in `or` binary operation tracking function leads to LPE
[CVE-2020-27194] Linux kernel: eBPF verifier bug in `or` binary operation tracking function leads to LPE
CVE-2020-27194 is a eBPF verifier bug that allows an unprivileged attacker to create BPF socket filter programs that can read and write Out of Bounds, trough which an arbitrary kernel read write can be achieved.
I'm taking the root cause explanation from the patch email:
```
Simon reported an issue with the current scalar32_min_max_or() implementation.
That is, compared to the other 32 bit subreg tracking functions, the code in
scalar32_min_max_or() stands out that it's using the 64 bit registers instead
of 32 bit ones. This leads to bounds tracking issues, for example:
[...]
8: R0=map_value(id=0,off=0,ks=4,vs=48,imm=0) R10=fp0 fp-8=mmmmmmmm
8: (79) r1 = *(u64 *)(r0 +0)
R0=map_value(
Bugzilla
CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c
bugzilla·2020-10-19·CVSS 5.5
CVE-2020-27194 [MEDIUM] CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c
CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values.
Reference and upstream patch:
https://github.com/torvalds/linux/commit/5b9fbeb75b6a98955f628e205ac26689bcb1383e
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1889479]
---
This was fixed for Fedora with the 5.8.15 stable kernel updates.
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-27194
---
Statement:
This flaw is rated as having a Moderate impact bec
Bugzilla
CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c [fedora-all]
bugzilla·2020-10-19·CVSS 5.5
CVE-2020-27194 [MEDIUM] CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c [fedora-all]
CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
arxiv_fulltext·2024-09-24
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
Bonan Ruan
National University of Singapore
Jiahao Liu
National University of Singapore
Chuqi Zhang
National University of Singapore
Zhenkai Liang
National University of Singapore
## Abstract
Linux kernel vulnerability reproduction is a critical task in system security.
To reproduce a kernel vulnerability, the vulnerable environment and the Proof of Concept (PoC) program are needed.
Most existing research focuses on the generation of PoC, while the construction of environment is overlooked.
However, establishing an effective vulnerable environment to trigger a vulnerability is challenging.
Firstly, it is hard to guarantee that the selected kernel version for reproduction is vulnerable, as the vulner
2020-10-16
Published