VDB

CVE-2020-27170

CVE-2020-27170 PUBLISHED

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

EPSS 0.15% · 35.5th percentile

Risk Scores

EPSS Score
0.15%
35.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlinux4.2.0-17.21, 4.4.0-11.26, 4.4.0-10.25
Ubuntu:18.04:LTSlinux-gke-5.35.3.0-1034.36, 0, 5.3.0-1012.13~18.04.1
Ubuntu:18.04:LTSlinux-raspi2-5.35.3.0-1019.21~18.04.1, 5.3.0-1018.20~18.04.1, 5.3.0-1021.23~18.04.1
Ubuntu:20.04:LTSlinux-gcp5.4.0-1025.25, 5.4.0-1022.22, 5.4.0-1021.21
Ubuntu:18.04:LTSlinux-aws-5.35.3.0-1017.18~18.04.1, *, *
Ubuntu:20.04:LTSlinux5.4.0-66.74, 5.4.0-62.70, 5.4.0-58.64
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-aws-fips0, 5.4.0-1021.21+fips2
Ubuntu:16.04:LTSlinux-oracle4.15.0-1066.74~16.04.1, *, *
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1081.88, 4.4.0-1083.90, 4.4.0-1086.93
Ubuntu:20.04:LTSlinux-hwe-5.85.8.0-23.24~20.04.1, 5.8.0-45.51~20.04.1, *
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1096.105, 4.15.0-1095.104, 4.15.0-1094.103
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:20.04:LTSlinux-aws5.4.0-1028.29, 5.4.0-1025.25, 5.4.0-1024.24
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1064.69~14.04.1, *, *
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-gkeop-5.40, 5.4.0-1001.1, 5.4.0-1003.3
Ubuntu:16.04:LTSlinux-hwe-edge4.8.0-28.30~16.04.1, 0, 4.15.0-22.24~16.04.1
Ubuntu:18.04:LTSlinux4.15.0-13.14, 4.15.0-36.39, 4.15.0-38.41
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-gcp-fips0, 5.4.0-1021.21+fips1
Ubuntu:20.04:LTSlinux-oem-5.105.10.0-1017.18, 5.10.0-1016.17, 5.10.0-1014.15

…and 57 more

Exploit Intelligence

Timeline

  • Mar 18, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›