CVE-2020-27777: High severity ibm data risk manager vulnerability
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel.
Other sources
Linux Kernel for PowerPC could allow a local authenticated attacker to bypass security restrictions, caused by a flaw with the Run-Time Abstraction Services (RTAS) interface. By sending a specially-crafted request, an attacker could exploit this vulnerability to overwrite some parts of memory, including kernel memory.
— IBM
The Linux kernel for powerpc has an issue with the Run-Time Abstraction Services (RTAS) interface, allowing root (or CAPSYSADMIN users) in a VM to overwrite some parts of memory, including kernel memory.
References: https://www.openwall.com/lists/oss-security/2020/10/09/1 https://www.openwall.com/lists/oss-security/2020/11/23/2
Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux.git/commit/?h=next&id=bd59380c5ba4147dcbaad3e582b55ccfd120b764
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-27777?
CVE-2020-27777 has been classified with a CVSS score indicating high severity due to its potential to allow privilege escalation on affected systems.
How do I fix CVE-2020-27777?
To fix CVE-2020-27777, update affected systems to the patched kernel versions provided by Red Hat or other relevant vendors.
Which systems are affected by CVE-2020-27777?
CVE-2020-27777 affects guest systems running on PowerVM or KVM hypervisors, especially those with Red Hat kernel versions 3.10, 4.18, and up to 5.10.
Can non-root users exploit CVE-2020-27777?
Yes, a local user with limited privileges can exploit CVE-2020-27777 to escalate their privileges on a vulnerable system.
Is CVE-2020-27777 specific to any Linux distributions?
CVE-2020-27777 primarily impacts Red Hat Enterprise Linux and related distributions running vulnerable kernel versions.