Skip to content

kernel CVE-2020-14385

High
webern published GHSA-wj7m-fx22-c4cf Nov 19, 2020

Package

kernel

Affected versions

< 1.0.3

Patched versions

1.0.3

Description

A flaw was found in the Linux kernel. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service.

Only local users, including unprivileged users in a container, can trigger this flaw. However, the impact could be high, especially on multi-tenant systems, because after the attack the system rendered inaccessible for some time (at least until reboot), so the impact has been increased to Important.

Severity

High

CVE ID

CVE-2020-14385

Weaknesses

No CWEs