** DISPUTED ** vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug.
References
Link | Resource |
---|---|
https://sourceware.org/git/?p=lvm2.git;a=commit;h=bcf9556b8fcd16ad8997f80cc92785f295c66701 | Mailing List Patch Third Party Advisory |
Configurations
Information
Published : 2020-02-13 21:15
Updated : 2022-01-01 11:52
NVD link : CVE-2020-8991
Mitre link : CVE-2020-8991
JSON object : View
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
Products Affected
redhat
- lvm2