CVE-2020-27170 PUBLISHED

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

EPSS 0.15% · 35.6th percentile

Risk Scores

EPSS Score
0.15%
35.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlinux4.4.0-14.30, 4.4.0-12.28, 4.4.0-11.26
Ubuntu:18.04:LTSlinux-gke-5.35.3.0-1030.32~18.04.1, 5.3.0-1026.28~18.04.1, 5.3.0-1032.34~18.04.1
Ubuntu:18.04:LTSlinux-raspi2-5.35.3.0-1019.21~18.04.1, 5.3.0-1021.23~18.04.1, 5.3.0-1022.24~18.04.1
Ubuntu:20.04:LTSlinux-gcp5.4.0-1032.34, 5.4.0-1029.31, 5.4.0-1028.29
Ubuntu:18.04:LTSlinux-aws-5.35.3.0-1032.34~18.04.2, 5.3.0-1033.35, 5.3.0-1034.36
Ubuntu:20.04:LTSlinux5.4.0-52.57, 5.4.0-48.52, 5.4.0-47.51
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-aws-fips0, 5.4.0-1021.21+fips2
Ubuntu:16.04:LTSlinux-oracle4.15.0-1046.50~16.04.1, 4.15.0-1050.54~16.04.1, 4.15.0-1051.55~16.04.1
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1085.92, 4.4.0-1002.2, 4.4.0-1001.1
Ubuntu:20.04:LTSlinux-hwe-5.85.8.0-45.51~20.04.1, 5.8.0-25.26~20.04.1, 5.8.0-28.30~20.04.1
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1079.86, 4.15.0-1093.102, 4.15.0-1094.103
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:20.04:LTSlinux-aws5.4.0-1028.29, 5.4.0-1029.30, 5.4.0-1030.31
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1098.109~14.04.1, 4.15.0-1100.111~14.04.1, 4.15.0-1102.113~14.04.1
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:18.04:LTSlinux-gkeop-5.45.4.0-1001.1, 0, 5.4.0-1011.12~18.04.2
Ubuntu:16.04:LTSlinux-hwe-edge4.13.0-16.19~16.04.3, 4.10.0-21.23~16.04.1, 4.10.0-20.22~16.04.1
Ubuntu:18.04:LTSlinux4.15.0-124.127, 4.15.0-128.131, 4.15.0-129.132
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-gcp-fips0, 5.4.0-1021.21+fips1
Ubuntu:20.04:LTSlinux-oem-5.105.10.0-1017.18, 5.10.0-1016.17, 5.10.0-1014.15

…and 57 more

Timeline

References

Open in Interactive Console →