// For flags

CVE-2020-15436

kernel: use-after-free in fs/block_dev.c

Severity Score

6.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.

La vulnerabilidad de tipo use-after-free en el archivo fs/block_dev.c en el kernel de Linux versiones anteriores a 5.8, permite a usuarios locales obtener privilegios o causar una denegaciĆ³n de servicio al aprovechar el acceso inapropiado a un determinado campo de error

A use-after-free flaw was observed in blkdev_get(), in fs/block_dev.c after a call to __blkdev_get() fails, and its refcount gets freed/released. This problem may cause a denial of service problem with a special user privilege, and may even lead to a confidentiality issue.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-06-30 CVE Reserved
  • 2020-11-23 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netapp
Search vendor "Netapp"
Solidfire Baseboard Management Controller Firmware
Search vendor "Netapp" for product "Solidfire Baseboard Management Controller Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Solidfire Baseboard Management Controller
Search vendor "Netapp" for product "Solidfire Baseboard Management Controller"
--
Safe
Netapp
Search vendor "Netapp"
H410c Firmware
Search vendor "Netapp" for product "H410c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H410c
Search vendor "Netapp" for product "H410c"
--
Safe
Netapp
Search vendor "Netapp"
H610c Firmware
Search vendor "Netapp" for product "H610c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H610c
Search vendor "Netapp" for product "H610c"
--
Safe
Netapp
Search vendor "Netapp"
H610s Firmware
Search vendor "Netapp" for product "H610s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H610s
Search vendor "Netapp" for product "H610s"
--
Safe
Netapp
Search vendor "Netapp"
H615c Firmware
Search vendor "Netapp" for product "H615c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H615c
Search vendor "Netapp" for product "H615c"
--
Safe
Netapp
Search vendor "Netapp"
A700s Firmware
Search vendor "Netapp" for product "A700s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
A700s
Search vendor "Netapp" for product "A700s"
--
Safe
Netapp
Search vendor "Netapp"
Aff 8700 Firmware
Search vendor "Netapp" for product "Aff 8700 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff 8700
Search vendor "Netapp" for product "Aff 8700"
--
Safe
Netapp
Search vendor "Netapp"
Fas 8700 Firmware
Search vendor "Netapp" for product "Fas 8700 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas 8700
Search vendor "Netapp" for product "Fas 8700"
--
Safe
Netapp
Search vendor "Netapp"
Aff 8300 Firmware
Search vendor "Netapp" for product "Aff 8300 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff 8300
Search vendor "Netapp" for product "Aff 8300"
--
Safe
Netapp
Search vendor "Netapp"
Fas 8300 Firmware
Search vendor "Netapp" for product "Fas 8300 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas 8300
Search vendor "Netapp" for product "Fas 8300"
--
Safe
Netapp
Search vendor "Netapp"
Aff A400 Firmware
Search vendor "Netapp" for product "Aff A400 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff A400
Search vendor "Netapp" for product "Aff A400"
--
Safe
Netapp
Search vendor "Netapp"
Fabric-attached Storage A400 Firmware
Search vendor "Netapp" for product "Fabric-attached Storage A400 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fabric-attached Storage A400
Search vendor "Netapp" for product "Fabric-attached Storage A400"
--
Safe
Netapp
Search vendor "Netapp"
A250 Firmware
Search vendor "Netapp" for product "A250 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
A250
Search vendor "Netapp" for product "A250"
--
Safe
Netapp
Search vendor "Netapp"
Aff 500f Firmware
Search vendor "Netapp" for product "Aff 500f Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff 500f
Search vendor "Netapp" for product "Aff 500f"
--
Safe
Netapp
Search vendor "Netapp"
Fas 500f Firmware
Search vendor "Netapp" for product "Fas 500f Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas 500f
Search vendor "Netapp" for product "Fas 500f"
--
Safe
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 2.6.38 < 4.4.229
Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.38 < 4.4.229"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 4.5 < 4.9.229
Search vendor "Linux" for product "Linux Kernel" and version " >= 4.5 < 4.9.229"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 4.10 < 4.14.186
Search vendor "Linux" for product "Linux Kernel" and version " >= 4.10 < 4.14.186"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 4.15 < 4.19.130
Search vendor "Linux" for product "Linux Kernel" and version " >= 4.15 < 4.19.130"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 4.20 < 5.4.49
Search vendor "Linux" for product "Linux Kernel" and version " >= 4.20 < 5.4.49"
-
Affected
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
>= 5.5 < 5.7.6
Search vendor "Linux" for product "Linux Kernel" and version " >= 5.5 < 5.7.6"
-
Affected
Broadcom
Search vendor "Broadcom"
Brocade Fabric Operating System Firmware
Search vendor "Broadcom" for product "Brocade Fabric Operating System Firmware"
--
Affected
Netapp
Search vendor "Netapp"
Cloud Backup
Search vendor "Netapp" for product "Cloud Backup"
--
Affected
Netapp
Search vendor "Netapp"
Solidfire \& Hci Management Node
Search vendor "Netapp" for product "Solidfire \& Hci Management Node"
--
Affected