CVE-2020-27171: Canonical Ubuntu Linux
Medium severity, CVSS 6.0. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
- Linux Linux Kernel: before 5.11.8 (fixed in 5.11.8)
Published 2021-03-20. Last modified 2026-10-08.