Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-27777
HistoryDec 15, 2020 - 12:00 a.m.

CVE-2020-27777

2020-12-1500:00:00
ubuntu.com
ubuntu.com
47
cve-2020-27777
rtas
memory access
user space
kernel communication
secure boot
powervm
kvm hypervisors
pseries platform
privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A flaw was found in the way RTAS handled memory accesses in userspace to
kernel communication. On a locked down (usually due to Secure Boot) guest
system running on top of PowerVM or KVM hypervisors (pseries platform) a
root like local user could use this flaw to further increase their
privileges to that of a running kernel.

Notes

Author Note
sbeattie fix needs typo correction from lkml link in refs
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-129.132UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-59.65UNKNOWN
ubuntu20.10noarchlinux< 5.8.0-44.50UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-201.233UNKNOWN
ubuntu18.04noarchlinux-dell300x< 4.15.0-1010.14UNKNOWN
ubuntu18.04noarchlinux-gke-5.4< 5.4.0-1033.35~18.04.1UNKNOWN
ubuntu18.04noarchlinux-gkeop-5.4< 5.4.0-1008.9~18.04.1UNKNOWN
ubuntu16.04noarchlinux-hwe< 4.15.0-129.132~16.04.1UNKNOWN
ubuntu18.04noarchlinux-hwe-5.4< 5.4.0-59.65~18.04.1UNKNOWN
ubuntu20.04noarchlinux-hwe-5.8< 5.8.0-44.50~20.04.1UNKNOWN
Rows per page:
1-10 of 111

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%