LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-14871: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-14871 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

CVE-2020-14871 is an unspecified vulnerability in Oracle Solaris and the Zettabyte File System (ZFS), including related Oracle ZFS Storage Appliance Kit components. It is associated with CWE-787 (out-of-bounds write) and can produce high impacts to confidentiality, integrity, and availability on affected systems. Defenders should treat it as a priority for inventory and patching because successful abuse of this class of flaw can allow an attacker to corrupt memory and disrupt or take control of critical storage and operating-system functions. Confirm all product, version, and configuration details against the vendor advisory before acting.

How it works

CWE-787 describes an out-of-bounds write: software writes data past the end or before the beginning of an intended buffer. In kernel or storage-stack code such as Solaris and ZFS, that mistake can overwrite adjacent memory structures that control process state, file-system metadata, or privilege boundaries. An attacker who can reach the vulnerable code path may trigger the write with crafted input, leading to crashes, data corruption, or further memory-safety failures that undermine system integrity. Exact trigger conditions, required privileges, and network versus local exposure are not specified in the public summary; treat the flaw as capable of high impact and verify the precise attack surface in Oracle’s advisory. No exploit mechanics beyond the CWE class are assumed here.

Am I affected? How to find it in your systems

Oracle Solaris hosts and appliances that implement or expose ZFS are the primary targets. These systems commonly appear as enterprise servers, storage arrays, and backup or NAS appliances running Oracle’s ZFS Storage Appliance Kit. Inventory steps:

Because the vulnerability is labeled unspecified, any Solaris/ZFS deployment should be checked until the advisory confirms it is outside scope.

How to remediate

Apply the updates published by Oracle for Solaris and the ZFS Storage Appliance Kit exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; that remains the primary fix. After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls appropriate to an out-of-bounds write in a storage/OS component:

These measures buy time but do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities of this severity can lead to full system compromise and subsequent data theft or ransomware, although ransomware use specifically tied to CVE-2020-14871 is not documented in the supplied facts. If compromise is suspected, isolate the host, preserve volatile evidence, and begin incident-response procedures focused on storage integrity and credential rotation. As a routine hygiene step, organizations and individuals can run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · Solaris and Zettabyte File System (ZFS)
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities