Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28085
HistoryDec 06, 2020 - 2:28 a.m.

Privilege Escalation

2020-12-0602:28:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24
linux
kvm
privilege escalation
incomplete permission checking
rbd block devices
vulnerability

EPSS

0

Percentile

5.1%

linux-kvm is vulnerable to privilege escalation. The vulnerability exists as the rbd block device driver in drivers/block/rbd.c used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices.