VDB

DEBIAN-CVE-2020-28374

DEBIAN-CVE-2020-28374 PUBLISHED CVSS 8.100000381469727 HIGH

In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Debian:11linux0, 0, 0
Debian:14linux0, 0, 0
Debian:12linux0, 0, 0
Debian:13linux0, 0, 0

Timeline

  • Jan 13, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›