Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8991

Опубликовано: 05 фев. 2020
Источник: redhat
CVSS3: 2.3

Описание

vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug

Отчет

The lvm2 package as shipped with Red Hat Enterprise Linux 8 is not affected as it doesn't contains the affected component (lvmetad).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5lvm2Out of support scope
Red Hat Enterprise Linux 6lvm2Out of support scope
Red Hat Enterprise Linux 7lvm2Fix deferred
Red Hat Enterprise Linux 8lvm2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=1805922lvm2: memory leak in vg_lookup in daemons/lvmetad/lvmetad-core.c

2.3 Low

CVSS3

Связанные уязвимости

CVSS3: 2.3
ubuntu
почти 6 лет назад

vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug

CVSS3: 2.3
nvd
почти 6 лет назад

vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug

CVSS3: 2.3
debian
почти 6 лет назад

vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages me ...

CVSS3: 2.3
github
больше 3 лет назад

vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs.

2.3 Low

CVSS3