CVE-2020-27777: Linux Kernel
Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel.
Affected products
- Linux Linux Kernel: before 4.14.204 (fixed in 4.14.204); from 4.15, before 4.19.155 (fixed in 4.19.155); from 4.20, before 5.4.75 (fixed in 5.4.75); from 5.5, before 5.9.5 (fixed in 5.9.5)
- Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only; version 8.0 only
- Red Hat Openshift Container Platform: version 4.4 only; version 4.5 only; version 4.6 only
Published 2020-12-15. Last modified 2026-06-17.