Unrated severityNVD Advisory· Published Sep 15, 2020· Updated Aug 4, 2024
CVE-2020-14385
CVE-2020-14385
Description
A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Affected products
32- osv-coords31 versionspkg:rpm/opensuse/kernel-debug&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-preempt&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-rt_debug&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-source-rt&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kernel-syms-rt&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP2pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/kernel-livepatch-SLE15-SP2_Update_4&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP2pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/kernel-preempt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/kernel-preempt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2
< 5.3.18-lp152.44.1+ 30 more
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.44.1.lp152.8.8.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.3.5.1
- (no CPE)range: < 5.3.18-lp152.3.5.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.3.5.1
- (no CPE)range: < 5.3.18-lp152.44.1
- (no CPE)range: < 5.3.18-lp152.3.5.1
- (no CPE)range: < 5.3.18-18.21.1
- (no CPE)range: < 5.3.18-24.24.1.9.7.6
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 1-5.3.6
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-18.21.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-24.24.1
- (no CPE)range: < 5.3.18-18.21.1
- (no CPE)range: < 5.3.18-24.24.1
- Linux Kernel/kernelv5Range: before 5.9-rc4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlmitrevendor-advisoryx_refsource_SUSE
- usn.ubuntu.com/4576-1/mitrevendor-advisoryx_refsource_UBUNTU
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2020/09/msg00025.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.