{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2020-11935","assignerOrgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","assignerShortName":"canonical","dateUpdated":"2024-08-04T11:42:00.593Z","dateReserved":"2020-04-20T00:00:00.000Z","datePublished":"2023-04-07T00:00:00.000Z"},"containers":{"cna":{"title":"aufs: improperly managed inode reference counts in the vfsub_dentry_open() method","providerMetadata":{"orgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","shortName":"canonical","dateUpdated":"2023-04-07T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack."}],"affected":[{"vendor":"Ubuntu","product":"Linux kernel (aufs filesystem module)","versions":[{"version":"4.4.0-186.216","status":"unaffected","lessThan":"4.4*","versionType":"custom"},{"version":"4.15.0-112.113","status":"unaffected","lessThan":"4.15*","versionType":"custom"},{"version":"5.4.0-42.46","status":"unaffected","lessThan":"5.4*","versionType":"custom"}]}],"references":[{"name":"Ubuntu Security CVE-2020-11935","tags":["vendor-advisory"],"url":"https://ubuntu.com/security/CVE-2020-11935"},{"name":"Launchpad Bug 1873074","tags":["vendor-advisory"],"url":"https://bugs.launchpad.net/bugs/1873074"}],"credits":[{"lang":"en","value":"Mauricio Faria de Oliveira discovered that the aufs implementation in the Linux kernel improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.4,"baseSeverity":"MEDIUM"}}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-911 Improper Update of Reference Count","cweId":"CWE-911"}]}],"x_generator":{"engine":"Vulnogram 0.0.9"},"source":{"defect":["LP#1873074"],"discovery":"USER"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T11:42:00.593Z"},"title":"CVE Program Container","references":[{"name":"Ubuntu Security CVE-2020-11935","tags":["vendor-advisory","x_transferred"],"url":"https://ubuntu.com/security/CVE-2020-11935"},{"name":"Launchpad Bug 1873074","tags":["vendor-advisory","x_transferred"],"url":"https://bugs.launchpad.net/bugs/1873074"}]}]}}