Severity
5.5MEDIUMNVD
EPSS
4.3%
top 11.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateSep 24

Description

An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDlinux/linux_kernel< 5.8.15
Debianlinux/linux_kernel< 5.9.1-1+3
debiandebian/linux< linux 5.9.1-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r8fj-347g-p44m: An issue was discovered in the Linux kernel before 52022-05-24
OSV
CVE-2020-27194: An issue was discovered in the Linux kernel before 52020-10-16

📋Vendor Advisories

4
Ubuntu
Linux kernel vulnerabilities2020-11-11
Microsoft
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values aka CID-5b9fbeb75b6a.2020-10-13
Red Hat
kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c2020-10-08
Debian
CVE-2020-27194: linux - An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or i...2020

📄Research Papers

1
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities2024-09-24

💬Community

3
HackerOne
[CVE-2020-27194] Linux kernel: eBPF verifier bug in `or` binary operation tracking function leads to LPE2021-07-23
Bugzilla
CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c2020-10-19
Bugzilla
CVE-2020-27194 kernel: bounds tracking issue during use of 64-bit values in scalar32_min_max_or function in kernel/bpf/verifier.c [fedora-all]2020-10-19