cbcvebase.
CVE-2020-27815
published 2021-05-26

CVE-2020-27815: A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.79%
52.1th percentile
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.10.4-1 (bookworm)linux 5.10.4-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.4-15.10.4-1
linuxlinux_kernel>= 0 < 5.10.4-15.10.4-1
linuxlinux_kernel>= 0 < 5.10.4-15.10.4-1
linuxlinux_kernel>= 0 < 5.10.4-15.10.4-1
linuxlinux_kernel>= 0 < 4.4.0-203.2354.4.0-203.235
linuxlinux_kernel>= 0 < 4.15.0-136.1404.15.0-136.140
linuxlinux_kernel>= 0 < 5.4.0-66.745.4.0-66.74
linuxlinux_kernel>= 4.10 < 4.14.2134.14.213
linuxlinux_kernel>= 4.15 < 4.19.1644.19.164
linuxlinux_kernel>= 4.20 < 5.4.865.4.86
linuxlinux_kernel>= 4.5 < 4.9.2494.9.249
linuxlinux_kernel>= 5.5 < 5.10.45.10.4
msrcazl3_kernel_6.6.29.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.135.1-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.1MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.