SB2020021443 - Input validation error in libffi lvm2



SB2020021443 - Input validation error in libffi lvm2

Published: February 14, 2020 Updated: August 8, 2020

Security Bulletin ID SB2020021443
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2020-8991)

The vulnerability allows a local privileged user to perform service disruption.

** DISPUTED ** vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug.


Remediation

Install update from vendor's website.