CVE-2020-8991 describes a memory leak in the vg_lookup function within the lvmetad-core.c component of LVM2 2.02, specifically affecting Red Hat LVM2 products. This vulnerability has a low CVSS score of 2.3, indicating a local attack vector with high privileges required, and its primary impact is a low availability concern due to the memory leak. Despite being a memory mismanagement issue (CWE-401), Red Hat disputes its classification as a vulnerability due to the lack of apparent routes to privilege escalation or denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.02.00CPE matchmatch criteria | cpe:2.3:a:redhat:lvm2:2.02.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.