Buffer overflow in Linux kernel - CVE-2020-14385

 

Buffer overflow in Linux kernel - CVE-2020-14385

Published: December 13, 2021


Vulnerability identifier: #VU58841
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14385
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in the file system metadata validator in XFS. A local user can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt and shutdown the the filesystem.


Affected software

Linux kernel
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Real Time - Telecommunications Update Service
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
kpatch-patch-3_10_0-1160_6_1 (Red Hat package)
kpatch-patch-3_10_0-1160_2_2 (Red Hat package)
kpatch-patch-3_10_0-1160_2_1 (Red Hat package)
kpatch-patch-3_10_0-1160 (Red Hat package)
kpatch-patch-4_18_0-147_24_2 (Red Hat package)
kpatch-patch-4_18_0-147_27_1 (Red Hat package)
kpatch-patch-4_18_0-147_20_1 (Red Hat package)
kpatch-patch-4_18_0-147_13_2 (Red Hat package)
kpatch-patch-4_18_0-147_8_1 (Red Hat package)
kpatch-patch-4_18_0-147_5_1 (Red Hat package)
kpatch-patch-4_18_0-147_0_2 (Red Hat package)
kpatch-patch-4_18_0-147_0_3 (Red Hat package)
kpatch-patch-4_18_0-147_3_1 (Red Hat package)
kpatch-patch-4_18_0-147 (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
perf
kernel-tools-devel
python3-perf
kernel-tools-debuginfo
perf-debuginfo
python2-perf
python2-perf-debuginfo
python3-perf-debuginfo
kernel-tools
kernel-source
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool
kernel
bpftool-debuginfo
kernel-headers
kernel-tools-libs-devel
kernel-tools-libs
python-perf
kernel-debug-devel
kernel-debug
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-oem-osp1 (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-lowlatency-hwe-20.04 (Ubuntu package)
linux-image-oem (Ubuntu package)
linux-image-5.4.0-51-lowlatency (Ubuntu package)
linux-image-5.4.0-51-generic (Ubuntu package)
linux-image-5.4.0-51-generic-lpae (Ubuntu package)
linux-image-generic-lpae-hwe-18.04 (Ubuntu package)
linux-image-virtual-hwe-18.04 (Ubuntu package)
linux-image-snapdragon-hwe-18.04 (Ubuntu package)
linux-image-lowlatency-hwe-18.04 (Ubuntu package)
linux-image-generic-hwe-18.04 (Ubuntu package)
linux-image-5.4.0-1021-raspi (Ubuntu package)
linux-image-raspi-hwe-18.04 (Ubuntu package)
linux-image-raspi2 (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-5.4.0-1026-kvm (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-5.4.0-1028-aws (Ubuntu package)
linux-image-5.4.0-1028-oracle (Ubuntu package)
linux-image-5.4.0-1028-gcp (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-5.4.0-1031-azure (Ubuntu package)
Data Computing Appliance (DCA)
IBM QRadar Network Security
Session Smart Router

How to mitigate CVE-2020-14385

Install updates from vendor's website.

Linux kernel - update to 5.9 rc4
kpatch-patch-3_10_0-1160_6_1 (Red Hat package) - update to 1-1.el7
kpatch-patch-3_10_0-1160_2_2 (Red Hat package) - update to 1-1.el7
kpatch-patch-3_10_0-1160_2_1 (Red Hat package) - update to 1-1.el7
kpatch-patch-3_10_0-1160 (Red Hat package) - update to 1-1.el7
kpatch-patch-4_18_0-147_24_2 (Red Hat package) - update to 1-2.el8_1
kpatch-patch-4_18_0-147_27_1 (Red Hat package) - update to 1-2.el8_1
kpatch-patch-4_18_0-147_20_1 (Red Hat package) - update to 1-4.el8_1
kpatch-patch-4_18_0-147_13_2 (Red Hat package) - update to 1-5.el8_1
kpatch-patch-4_18_0-147_8_1 (Red Hat package) - update to 1-7.el8_1
kpatch-patch-4_18_0-147_5_1 (Red Hat package) - update to 1-9.el8_1
kpatch-patch-4_18_0-147_0_2 (Red Hat package) - update to 1-14.el8
kpatch-patch-4_18_0-147_0_3 (Red Hat package) - update to 1-14.el8
kpatch-patch-4_18_0-147_3_1 (Red Hat package) - update to 1-14.el8_1
kpatch-patch-4_18_0-147 (Red Hat package) - update to 1-18.el8
kernel (Red Hat package) - addressed in versions 3.10.0-1160.11.1.el7, 4.18.0-80.31.1.el8_0, 4.18.0-147.32.1.el8_1, 4.18.0-193.28.1.el8_2
kernel-rt (Red Hat package) - addressed in versions 3.10.0-1160.11.1.rt56.1145.el7, 4.18.0-193.28.1.rt13.77.el8_2
Data Computing Appliance (DCA) - update to 4.3.0.0
perf - update to 4.19.90-2010.2.0.0046
kernel-tools-devel - update to 4.19.90-2010.2.0.0046
python3-perf - update to 4.19.90-2010.2.0.0046
kernel-tools-debuginfo - update to 4.19.90-2010.2.0.0046
perf-debuginfo - update to 4.19.90-2010.2.0.0046
python2-perf - update to 4.19.90-2010.2.0.0046
python2-perf-debuginfo - update to 4.19.90-2010.2.0.0046
python3-perf-debuginfo - update to 4.19.90-2010.2.0.0046
kernel-tools - update to 4.19.90-2010.2.0.0046
kernel-source - update to 4.19.90-2010.2.0.0046
kernel-devel - update to 4.19.90-2010.2.0.0046
kernel-debugsource - update to 4.19.90-2010.2.0.0046
kernel-debuginfo - update to 4.19.90-2010.2.0.0046
bpftool - update to 4.19.90-2010.2.0.0046
kernel - update to 4.19.90-2010.2.0.0046
bpftool-debuginfo - update to 4.19.90-2010.2.0.0046
kernel-headers - update to 4.19.91-26
perf - update to 4.19.91-26
kernel-tools-libs-devel - update to 4.19.91-26
kernel-tools-libs - update to 4.19.91-26
kernel-tools - update to 4.19.91-26
python-perf - update to 4.19.91-26
kernel-devel - update to 4.19.91-26
kernel-debug-devel - update to 4.19.91-26
kernel-debug - update to 4.19.91-26
kernel - update to 4.19.91-26
bpftool - update to 4.19.91-26
IBM QRadar Network Security - addressed in versions 5.4.0.17, 5.5.0.12
linux-image-virtual-hwe-20.04 (Ubuntu package) - update to 5.4.0.51.54
linux-image-generic (Ubuntu package) - update to 5.4.0.51.54
linux-image-generic-hwe-20.04 (Ubuntu package) - update to 5.4.0.51.54
linux-image-generic-lpae (Ubuntu package) - update to 5.4.0.51.54
linux-image-generic-lpae-hwe-20.04 (Ubuntu package) - update to 5.4.0.51.54
linux-image-virtual (Ubuntu package) - update to 5.4.0.51.54
linux-image-oem-osp1 (Ubuntu package) - update to 5.4.0.51.54
linux-image-lowlatency (Ubuntu package) - update to 5.4.0.51.54
linux-image-lowlatency-hwe-20.04 (Ubuntu package) - update to 5.4.0.51.54
linux-image-oem (Ubuntu package) - update to 5.4.0.51.54
linux-image-5.4.0-51-lowlatency (Ubuntu package) - update to 5.4.0-51.56~18.04.1
linux-image-5.4.0-51-generic (Ubuntu package) - update to 5.4.0-51.56~18.04.1
linux-image-5.4.0-51-generic-lpae (Ubuntu package) - update to 5.4.0-51.56~18.04.1
linux-image-generic-lpae-hwe-18.04 (Ubuntu package) - update to 5.4.0.51.56~18.04.45
linux-image-virtual-hwe-18.04 (Ubuntu package) - update to 5.4.0.51.56~18.04.45
linux-image-snapdragon-hwe-18.04 (Ubuntu package) - update to 5.4.0.51.56~18.04.45
linux-image-lowlatency-hwe-18.04 (Ubuntu package) - update to 5.4.0.51.56~18.04.45
linux-image-generic-hwe-18.04 (Ubuntu package) - update to 5.4.0.51.56~18.04.45
linux-image-5.4.0-1021-raspi (Ubuntu package) - update to 5.4.0-1021.24~18.04.1
linux-image-raspi-hwe-18.04 (Ubuntu package) - update to 5.4.0.1021.25
linux-image-raspi2 (Ubuntu package) - update to 5.4.0.1021.56
linux-image-raspi (Ubuntu package) - update to 5.4.0.1021.56
linux-image-kvm (Ubuntu package) - update to 5.4.0.1026.24
linux-image-5.4.0-1026-kvm (Ubuntu package) - update to 5.4.0-1026.27
linux-image-oracle (Ubuntu package) - addressed in versions 5.4.0.1028.12, 5.4.0.1028.25
linux-image-aws (Ubuntu package) - addressed in versions 5.4.0.1028.13, 5.4.0.1028.29
linux-image-gcp (Ubuntu package) - addressed in versions 5.4.0.1028.16, 5.4.0.1028.36
linux-image-5.4.0-1028-aws (Ubuntu package) - update to 5.4.0-1028.29~18.04.1
linux-image-5.4.0-1028-oracle (Ubuntu package) - update to 5.4.0-1028.29~18.04.1
linux-image-5.4.0-1028-gcp (Ubuntu package) - update to 5.4.0-1028.29~18.04.1
linux-image-gke (Ubuntu package) - update to 5.4.0.1028.36
linux-image-azure (Ubuntu package) - addressed in versions 5.4.0.1031.13, 5.4.0.1031.29
linux-image-5.4.0-1031-azure (Ubuntu package) - update to 5.4.0-1031.32~18.04.1
Session Smart Router - addressed in versions 5.4.7, 5.5.3
kernel-headers - update to 5.8.6-200.fc32
kernel-tools - update to 5.8.6-200.fc32
kernel - update to 5.8.6-201.fc32

External References

Related Security Bulletins