← Vulnerability feed

Vulnerability record · CVE-2020-27678 · published 26 October 2020

CVE-2020-27678: Illumos classic buffer overflow vulnerability

Illumos · Illumos

An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.

9.8 CVSS 3.1 Critical EPSS 1.4% · top 27.7% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-8733Joyent smartos integer overflow vulnerabilityAn exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system …EPSS 0.55%8.6CVE-2016-6560Illumos improper input validation vulnerabilityillumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.EPSS 1.7%8.2CVE-2020-24718Freebsd missing authorization vulnerabilitybhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restr…EPSS 0.60%8.1CVE-2019-9579Illumos incorrect default permissions vulnerabilityAn issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended a…EPSS 0.50%7.8CVE-2018-1166Joyent smartos use after free vulnerabilityThis vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An …EPSS 0.38%7.8CVE-2016-9031Joyent smartos integer overflow vulnerabilityAn exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system …EPSS 0.49%7.5CVE-2019-19396Omniosce omnios improper input validation vulnerabilityillumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurre…EPSS 1.1%7.5CVE-2016-6561Illumos null pointer dereference vulnerabilityillumos smbsrv NULL pointer dereference allows system crash.EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2020-27678), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.