CVE-2020-27815
Public on 2021-01-25
Modified on 2021-01-26
Description
A flaw was found in the JFS filesystem code. This flaw allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 1 | kernel | 2021-01-26 | ALAS-2021-1477 | Fixed |
| Amazon Linux 2 - Core | kernel | 2021-01-26 | ALAS2-2021-1588 | Fixed |
| Amazon Linux 2 - Kernel-5.4 Extra | kernel | 2022-01-28 | ALAS2KERNEL-5.4-2022-019 | Fixed |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.4 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |