CVE-2020-28374
published 2021-01-13CVE-2020-28374: In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote…
PriorityP358high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
6.31%
92.9th percentile
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.10.9-1 (bookworm) | linux 5.10.9-1 (bookworm) |
| debian | tcmu | < tcmu 1.5.2-6 (bookworm) | tcmu 1.5.2-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 5.10.7 | 5.10.7 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 5.10.9-1 | 5.10.9-1 |
| linux | linux_kernel | >= 0 < 4.4.0-262.296 | 4.4.0-262.296 |
| linux | linux_kernel | >= 0 < 4.15.0-132.136 | 4.15.0-132.136 |
| linux | linux_kernel | >= 0 < 5.4.0-62.70 | 5.4.0-62.70 |
| msrc | cm1_kernel_5.4.91-1_on_cbl_mariner_1.0 | — | — |
| tcmu-runner_project | tcmu-runner | 1.3.0 – 1.5.2 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2021-04-06·CVSS 8.1
CVE-2021-27365 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Adam Nichols discovered that heap overflows existed in the iSCSI subsystem
in the Linux kernel. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2021-27365)
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data. (CVE-2020-28374)
Adam Nichols discovered that the iSCSI subsystem in the Linux kernel did
not properly restrict access to iSCSI transport handles. A local attacker
co
Ubuntu
Linux kernel (OEM) vulnerability
vendor_ubuntu·2021-02-25
CVE-2020-28374 Linux kernel (OEM) vulnerability
Title: Linux kernel (OEM) vulnerability
Summary: The system could allow unintended access to data in some environments.
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2021-02-10
CVE-2020-28374 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could allow unintended access to data in some environments.
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. lin
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-02-05·CVSS 5.5
CVE-2020-28374 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data. (CVE-2020-28374)
Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel did
not properly deallocate memory in some situations. A privileged attacker
could use this to cause a denial of service (kernel memory exhaustion).
(CVE-2020-25704)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI chan
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-02-02·CVSS 5.5
CVE-2020-28374 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data. (CVE-2020-28374)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
It was discovered that the btrfs file system implementation in the Linux
kernel did not properly validate file system met
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2021-01-26·CVSS 5.5
CVE-2020-28374 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Elena Petrova discovered that the pin controller device tree implementation
in the Linux kernel did not properly handle string references. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-0427)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux
kernel did not properly initialize memory in some situations. A physically
proximate remote attacker could use this to expose sensitive information
(kernel memory). (CVE-2020-12352)
It was discovered that the GENEVE tunnel implementation in the Linux kernel
when combined with IPSec did not properly select IP routes in some
situations. An attacker could use this to expose sensitive i
Red Hat
tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
vendor_redhat·2021-01-13·CVSS 8.1
CVE-2021-3139 [HIGH] CWE-20 tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
A flaw was found in the Linux kernel’s implementation of the Linux SCSI target host, where an authenticated attacker could write to any block on the exported SCSI device backing store. This flaw allows an authenticated attacker to send LIO block requests to the Linux system to overwrite data on the back
Red Hat
kernel: SCSI target (LIO) write to any block on ILO backstore
vendor_redhat·2021-01-13·CVSS 8.1
CVE-2020-28374 [HIGH] CWE-20 kernel: SCSI target (LIO) write to any block on ILO backstore
kernel: SCSI target (LIO) write to any block on ILO backstore
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
A flaw was found in the Linux kernel’s implementation of the Linux SCSI target host, where an authenticated attacker could write to any block on the exported SCSI device backing store. This flaw allows an authenticated attacker to send LIO block requests to the Linux syst
Microsoft
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via director
vendor_msrc·2021-01-12·CVSS 8.1
CVE-2020-28374 [HIGH] CWE-22 In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via director
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request aka CID-2896c93811e3. For example an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
Debian
CVE-2021-3139: tcmu - In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_ud...
vendor_debian·2021·CVSS 8.1
CVE-2021-3139 [HIGH] CVE-2021-3139: tcmu - In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_ud...
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
Scope: local
bookworm: resolved (fixed in 1.5.2-6)
bullseye: resolved (fixed in 1.5.2-6)
forky: resolved (fixed in 1.5.2-6)
sid: resolved (fixed in 1.5.2-6)
trixie: resolved (fixed in 1.5.2-6)
Debian
CVE-2020-28374: linux - In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insuffi...
vendor_debian·2020·CVSS 8.1
CVE-2020-28374 [HIGH] CVE-2020-28374: linux - In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insuffi...
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
Scope: local
bookworm: resolved (fixed in 5.10.9-1)
bullseye: resolved (fixed in 5.10.9-1)
forky: resolved (fixed in 5.10.9-1)
sid: resolved (fixed in 5.10.9-1)
trixie: resolved (fixed in 5.10.9-1)
GHSA
GHSA-xp87-7m9f-4cr9: In drivers/target/target_core_xcopy
ghsa_unreviewed·2022-05-24
CVE-2020-28374 [HIGH] CWE-22 GHSA-xp87-7m9f-4cr9: In drivers/target/target_core_xcopy
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
GHSA
GHSA-j364-gjm2-cwx8: In Open-iSCSI tcmu-runner 1
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2021-3139 [HIGH] CWE-22 GHSA-j364-gjm2-cwx8: In Open-iSCSI tcmu-runner 1
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
OSV
linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2021-02-05·CVSS 5.5
CVE-2020-28374 [MEDIUM] linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data. (CVE-2020-28374)
Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel did
not properly deallocate memory in some situations. A privileged attacker
could use this to cause a denial of service (kernel memory exhaustion).
(CVE-2020-25704)
OSV
linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2021-02-02·CVSS 5.5
CVE-2020-28374 [MEDIUM] linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data. (CVE-2020-28374)
Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)
It was discovered that the btrfs file system implementation in the Linux
kernel did not properly validate file system metadata in some situations.
An atta
OSV
Kernel Live Patch Security Notice
osv·2021-01-26·CVSS 5.5
CVE-2020-0427 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Elena Petrova discovered that the pin controller device tree implementation
in the Linux kernel did not properly handle string references. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-0427)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux
kernel did not properly initialize memory in some situations. A physically
proximate remote attacker could use this to expose sensitive information
(kernel memory). (CVE-2020-12352)
It was discovered that the GENEVE tunnel implementation in the Linux kernel
when combined with IPSec did not properly select IP routes in some
situations. An attacker could use this to expose sensitive information
(unencrypted network traffic). (CVE-2020-25645)
It was
OSV
CVE-2020-28374: In drivers/target/target_core_xcopy
osv·2021-01-13·CVSS 8.1
CVE-2020-28374 [HIGH] CVE-2020-28374: In drivers/target/target_core_xcopy
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
OSV
CVE-2021-3139: In Open-iSCSI tcmu-runner 1
osv·2021-01-13·CVSS 8.1
CVE-2021-3139 [HIGH] CVE-2021-3139: In Open-iSCSI tcmu-runner 1
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
Kernel
scsi: target: Fix XCOPY NAA identifier lookup
kernel_security·2020-11-03·CVSS 8.1
CVE-2020-28374 [HIGH] scsi: target: Fix XCOPY NAA identifier lookup
scsi: target: Fix XCOPY NAA identifier lookup
When attempting to match EXTENDED COPY CSCD descriptors with corresponding
se_devices, target_xcopy_locate_se_dev_e4() currently iterates over LIO's
global devices list which includes all configured backstores.
This change ensures that only initiator-accessible backstores are
considered during CSCD descriptor lookup, according to the session's
se_node_acl LUN list.
To avoid LUN removal race conditions, device pinning is changed from being
configfs based to instead using the se_node_acl lun_ref.
Reference: CVE-2020-28374
Fixes: cbf031f425fd ("target: Add support for EXTENDED_COPY copy offload emulation")
Reviewed-by: Lee Duncan
Signed-off-by: David Disseldorp
Signed-off-by: Mike Christie
Signed-off-by: Martin K. Petersen
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.htmlhttp://www.openwall.com/lists/oss-security/2021/01/13/2http://www.openwall.com/lists/oss-security/2021/01/13/5https://bugzilla.suse.com/attachment.cgi?id=844938https://bugzilla.suse.com/show_bug.cgi?id=1178372https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.7https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2896c93811e39d63a4d9b63ccf12a8fbc226e5e4https://github.com/torvalds/linux/commit/2896c93811e39d63a4d9b63ccf12a8fbc226e5e4https://lists.debian.org/debian-lts-announce/2021/02/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZEUPID5DZYLZBIO4BEVLHFUDZZIFL57/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HK7SRTITN5ABAUOOIGFVR7XE5YKYYAVO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LTGQDYIEO2GOCOOKADBHEITF44GY55QF/https://security.netapp.com/advisory/ntap-20210219-0002/https://www.debian.org/security/2021/dsa-4843http://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.htmlhttp://www.openwall.com/lists/oss-security/2021/01/13/2http://www.openwall.com/lists/oss-security/2021/01/13/5https://bugzilla.suse.com/attachment.cgi?id=844938https://bugzilla.suse.com/show_bug.cgi?id=1178372https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.7https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2896c93811e39d63a4d9b63ccf12a8fbc226e5e4https://github.com/torvalds/linux/commit/2896c93811e39d63a4d9b63ccf12a8fbc226e5e4https://lists.debian.org/debian-lts-announce/2021/02/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZEUPID5DZYLZBIO4BEVLHFUDZZIFL57/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HK7SRTITN5ABAUOOIGFVR7XE5YKYYAVO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LTGQDYIEO2GOCOOKADBHEITF44GY55QF/https://security.netapp.com/advisory/ntap-20210219-0002/https://www.debian.org/security/2021/dsa-4843
2021-01-13
Published