Input validation error in lvm2 - CVE-2020-8991
Published: February 14, 2020 / Updated: August 8, 2020
lvm2
Detailed vulnerability description
The vulnerability allows a local privileged user to perform service disruption.
** DISPUTED ** vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug.