CVE-2020-27170: Canonical Ubuntu Linux

Medium severity, CVSS 4.7. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
  • Linux Linux Kernel: before 5.11.8 (fixed in 5.11.8)

Published 2021-03-20. Last modified 2026-10-08.