Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11935

Опубликовано: 07 апр. 2023
Источник: debian
EPSS Низкий

Описание

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
aufsunfixedpackage
aufsno-dsabusterpackage
aufsignoredstretchpackage

Примечания

  • To exploit the issue CONFIG_IMA in Kernel needs to be enabled.

  • linux/4.9.y had the config enabled, but was disabled in later versions

  • including linux/4.19.y.

  • https://sourceforge.net/p/aufs/mailman/message/37048642/

  • https://github.com/sfjro/aufs4-linux/commit/515a586eeef31e0717d5dea21e2c11a965340b3c

  • https://github.com/sfjro/aufs4-linux/commit/f10aea57d39d6cd311312e9e7746804f7059b5c8

EPSS

Процентиль: 10%
0.00034
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 3 года назад

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.

redhat
почти 6 лет назад

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.

CVSS3: 4.4
nvd
почти 3 года назад

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.

CVSS3: 5.5
github
почти 3 года назад

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.

CVSS3: 5.5
fstec
почти 6 лет назад

Уязвимость функции vfsub_dentry_open файловой системы Another UnionFS, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 10%
0.00034
Низкий