vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug
CVSS Details
- CVSS 3.1 Base Score: 2.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-lvm2 | Jul 30, 2024 | Feb 14, 2020 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-lvm2huawei-euleros-2_0_sp5-upgrade-lvm2-libshuawei-euleros-2_0_sp5-upgrade-lvm2-python-libs | Mar 24, 2020 | Feb 14, 2020 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Feb 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub