Lucene search

K
osvGoogleOSV:USN-4713-2
HistoryFeb 10, 2021 - 1:17 a.m.

linux, linux-gke-5.0, linux-gke-5.3, linux-hwe, linux-raspi2-5.3 vulnerability

2021-02-1001:17:36
Google
osv.dev
10
linux
lio scsi target
identifier checking
vulnerability
xcopy requests
backstore environment
sensitive information
modify data
software

AI Score

7.9

Confidence

High

EPSS

0.004

Percentile

72.9%

It was discovered that the LIO SCSI target implementation in the Linux
kernel performed insufficient identifier checking in certain XCOPY
requests. An attacker with access to at least one LUN in a multiple
backstore environment could use this to expose sensitive information or
modify data.