CVE-2020-27815

HIGH

Linux Kernel >=4.4.249 - Memory Corruption via JFS Extended Attributes

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-27815. PoCs published by Trinadh465.

AI-analyzed exploit summary This repository appears to be a documentation dump from a Linux kernel version (4.19.72) and does not contain exploit code or a proof-of-concept for CVE-2020-27815. The files provided are standard Linux kernel documentation and configuration scripts.

Description

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Exploits (1)

nomisec WRITEUP
by Trinadh465 · poc
https://github.com/Trinadh465/linux-4.19.72_CVE-2020-27815

This repository appears to be a documentation dump from a Linux kernel version (4.19.72) and does not contain exploit code or a proof-of-concept for CVE-2020-27815. The files provided are standard Linux kernel documentation and configuration scripts.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Linux kernel 4.19.72
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/11/30/5
Exploit, Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/12/28/1
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4843
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/02/msg00018.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210702-0004/

Scores

CVSS v3 7.8
EPSS 0.0078
EPSS Percentile 51.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-787
Status published
Products (13)
debian/debian_linux 9.0
debian/debian_linux 10.0
linux/linux_kernel 4.4.249
netapp/aff_a250_firmware
netapp/fas500f_firmware
netapp/h300e_firmware
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500e_firmware
... and 3 more
Published May 26, 2021
Tracked Since Feb 18, 2026