Lucene search

K
osvGoogleOSV:USN-4694-1
HistoryJan 14, 2021 - 11:48 p.m.

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-lts-xenial vulnerability

2021-01-1423:48:32
Google
osv.dev
15
linux kernel
lio scsi target
xcopy requests
multiple backstore environment
sensitive information
modify data
software

AI Score

7.9

Confidence

High

EPSS

0.004

Percentile

72.9%

It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data.