2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2020-15436" ,
"sourceIdentifier" : "securities@openeuler.org" ,
"published" : "2020-11-23T21:15:11.813" ,
2023-10-12 14:00:31 +00:00
"lastModified" : "2023-10-12T13:31:04.563" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Analyzed" ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field."
} ,
{
"lang" : "es" ,
"value" : "La vulnerabilidad de tipo use-after-free en el archivo fs/block_dev.c en el kernel de Linux versiones anteriores a 5.8, permite a usuarios locales obtener privilegios o causar una denegaci\u00f3n de servicio al aprovechar el acceso inapropiado a un determinado campo de error"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "HIGH" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 6.7 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 0.8 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C" ,
"accessVector" : "LOCAL" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
"availabilityImpact" : "COMPLETE" ,
"baseScore" : 7.2
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-416"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
2023-10-12 14:00:31 +00:00
"versionStartIncluding" : "2.6.38" ,
"versionEndExcluding" : "4.4.229" ,
"matchCriteriaId" : "DA9AE6DE-39FB-4119-AD8F-03D9E12D699F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.5" ,
"versionEndExcluding" : "4.9.229" ,
"matchCriteriaId" : "9C7D30FF-7984-4EB3-AF8A-0E29064F16AC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.10" ,
"versionEndExcluding" : "4.14.186" ,
"matchCriteriaId" : "AE916088-825A-4296-BD7D-7016A72F957A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.15" ,
"versionEndExcluding" : "4.19.130" ,
"matchCriteriaId" : "D43D9AB3-E226-4A4C-963C-2B77834AD8EC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.20" ,
"versionEndExcluding" : "5.4.49" ,
"matchCriteriaId" : "D0D47E73-D50E-4A82-B7B9-26452AD64BBE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.5" ,
"versionEndExcluding" : "5.7.6" ,
"matchCriteriaId" : "1D2A3E90-AD7E-4224-926C-E4B10ABFE1DB"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B2748912-FC54-47F6-8C0C-B96784765B8E"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5C2089EE-5D7F-47EC-8EA5-0F69790564C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:netapp:solidfire_\\&_hci_management_node:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D6D700C5-F67F-4FFB-BE69-D524592A3D2E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:solidfire_baseboard_management_controller_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FB9B8171-F6CA-427D-81E0-6536D3BBFA8D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "090AA6F4-4404-4E26-82AB-C3A22636F276"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "234DEFE0-5CE5-4B0A-96B8-5D227CB8ED31"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CDDF61B7-EC5C-467C-B710-B89F502CD04F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "89612649-BACF-4FAC-9BA4-324724FD93A6"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F3D9B255-C1AF-42D1-BF9B-13642FBDC080"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FD7CFE0E-9D1E-4495-B302-89C3096FC0DF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F63A3FA7-AAED-4A9D-9FDE-6195302DA0F6"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5921A877-18BF-43FE-915C-D226E140ACFC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7296A1F2-D315-4FD5-8A73-65C480C855BE"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDD92BFA-9117-4E6E-A13F-ED064B4B7284"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:a700s:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B7DA42F-5D64-4967-A2D4-6210FE507841"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:aff_8700_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "70ECC434-DF20-49A6-B4CF-D5CCA480E57D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:aff_8700:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "232DC609-8023-41F9-8CE3-1B31CE2F2D93"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:fas_8700_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF5AFE69-7990-4F80-9E63-D8AD58AA3A2D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:fas_8700:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6415E28A-4EAC-4F7F-BD81-1A55CE8B6F40"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:aff_8300_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA79D39A-A5F2-4C44-A805-5113065F8C25"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:aff_8300:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CA55FBD-6EBA-49C8-92BA-2B1BCCB18A3A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:fas_8300_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D5CDADAB-72A5-4526-8432-E6C9AC56B29F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:fas_8300:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E64576DE-90F0-4F5E-9C82-AB745CFEDBB7"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "56FD9B9A-BBE5-4CA5-B9F9-B16E1FE738C8"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:aff_a400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F3E70A56-DBA8-45C7-8C49-1A036501156F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:fabric-attached_storage_a400_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0BA5679F-B7F4-482B-92B3-52121124829F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:fabric-attached_storage_a400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "02F063AC-FC82-45E4-A977-243FB3569904"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1236B66D-EB11-4324-929F-E2B86683C3C7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "281DFC67-46BB-4FC2-BE03-3C65C9311F65"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:aff_500f_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "578BB9A7-BF28-4068-A9A6-1DE19CEEC293"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:aff_500f:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2AB58180-E5E0-4056-ABF9-A99E9F6A9E86"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:netapp:fas_500f_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "86E430A7-F93D-422B-BC9E-99C17CC2BF6F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:netapp:fas_500f:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DBC58E3E-C8AA-4400-8A48-733B321CC924"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://lkml.org/lkml/2020/6/7/379" ,
"source" : "securities@openeuler.org" ,
"tags" : [
"Exploit" ,
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20201218-0002/" ,
"source" : "securities@openeuler.org" ,
"tags" : [
"Third Party Advisory"
]
}
]
}