CVE-2020-27835

CVSS v3.1 4.4 (Medium)
44% Progress
CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 19

A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user calls Ioctl after open dev file and fork. A local user could use this flaw to crash the system.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2021-01-07 18:15:13
(3 years ago)
Updated Date
2021-01-14 15:12:37
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Infiniband Hfi1 Driver 5.9 and prior versions cpe:2.3:a:linux:infiniband_hfi1_driver <= 5.9
  Linux Infiniband Hfi1 Driver 5.10 Rc1 cpe:2.3:a:linux:infiniband_hfi1_driver:5.10:rc1
  Linux Infiniband Hfi1 Driver 5.10 Rc2 cpe:2.3:a:linux:infiniband_hfi1_driver:5.10:rc2
  Linux Infiniband Hfi1 Driver 5.10 Rc3 cpe:2.3:a:linux:infiniband_hfi1_driver:5.10:rc3
  Linux Infiniband Hfi1 Driver 5.10 Rc4 cpe:2.3:a:linux:infiniband_hfi1_driver:5.10:rc4
  Linux Infiniband Hfi1 Driver 5.10 Rc5 cpe:2.3:a:linux:infiniband_hfi1_driver:5.10:rc5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...