PT-2020-15828 · Openzfs · Openzfs

Published

2020-08-27

·

Updated

2020-09-04

·

CVE-2020-24717

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenZFS versions prior to 2.0.0-rc1
Description The issue misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777, leading to a disruption in access control. This occurs due to a critical flaw in the code added to OpenZFS for FreeBSD support, where group rights are processed as owner rights.
Recommendations For OpenZFS versions prior to 2.0.0-rc1, update to version 2.0.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24717

Affected Products

Openzfs