Cyber Resilience

CVE-2020-27171

MediumPublic PoC

Published: 20 March 2021

Published
20 March 2021
Modified
21 November 2024
KEV Added
Patch
19 March 2021
CVSS Score v3.1 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
EPSS Score 0.0018 39.3th percentile
Risk Priority 12 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2020-27171 is a medium-severity Off-by-one Error (CWE-193) vulnerability in Canonical Ubuntu Linux. Its CVSS base score is 6.0 (Medium).

Operationally, ranked at the 39.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel…

more

memory, aka CID-10d2bb2e6b1d.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

linux
linux kernel
≤ 5.11.8
fedoraproject
fedora
32, 33, 34
debian
debian linux
9.0
canonical
ubuntu linux
14.04, 16.04, 18.04, 20.04

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References