CVE-2020-36789
published 2025-04-17CVE-2020-36789: In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but
not always, the case), the 'WARN_ON(in_irq)' in
net/core/skbuff.c#skb_release_head_state() might be triggered, under network
congestion circumstances, together with the potential risk of a NULL pointer
dereference.
The root cause of this issue is the call to kfree_skb() instead of
dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog().
This patch prevents the skb to be freed within the call to netif_rx() by
incrementing its reference count with skb_get(). The skb is finally freed by
one of the in-irq-context safe functions: dev_consume_skb_any() or
dev_kfree_skb_any(). The "any" version is used because some drivers might call
can_get_echo_skb() in a normal context.
The reason for this issue to occur is that initially, in the core network
stack, loopback skb were not supposed to be received in hardware IRQ context.
The CAN stack is an exeption.
This bug was previously reported back in 2017 in [1] but the proposed patch
never got accepted.
While [1] directly modifies net/core/dev.c, we try to propose here a
smoother modification local to CAN network stack (the assumption
behind is that only CAN devices are affected by this issue).
[1] http://lore.kernel.org/r/[email protected]
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.9.9-1 (bookworm) | linux 5.9.9-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 248b71ce92d4f3a574b2537f9838f48e892618f4 | 248b71ce92d4f3a574b2537f9838f48e892618f4 |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 451187b20431924d13fcfecc500d7cd2d9951bac | 451187b20431924d13fcfecc500d7cd2d9951bac |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 3a922a85701939624484e7f2fd07d32beed00d25 | 3a922a85701939624484e7f2fd07d32beed00d25 |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 7e4cf2ec0ca236c3e5f904239cec6efe1f3baf22 | 7e4cf2ec0ca236c3e5f904239cec6efe1f3baf22 |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < ab46748bf98864f9c3f5559060bf8caf9df2b41e | ab46748bf98864f9c3f5559060bf8caf9df2b41e |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 87530b557affe01c764de32dbeb58cdf47234574 | 87530b557affe01c764de32dbeb58cdf47234574 |
| linux | linux | >= 39549eef3587f1c1e8c65c88a2400d10fd30ea17 < 2283f79b22684d2812e5c76fc2280aae00390365 | 2283f79b22684d2812e5c76fc2280aae00390365 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.9.9-1 | 5.9.9-1 |
| linux | linux_kernel | >= 0 < 5.9.9-1 | 5.9.9-1 |
| linux | linux_kernel | >= 0 < 5.9.9-1 | 5.9.9-1 |
| linux | linux_kernel | >= 0 < 5.9.9-1 | 5.9.9-1 |
| linux | linux_kernel | >= 2.6.31 < 4.4.244 | 4.4.244 |
| linux | linux_kernel | >= 4.10 < 4.14.207 | 4.14.207 |
| linux | linux_kernel | >= 4.15 < 4.19.158 | 4.19.158 |
| linux | linux_kernel | >= 4.20 < 5.4.78 | 5.4.78 |
| linux | linux_kernel | >= 4.5 < 4.9.244 | 4.9.244 |
| linux | linux_kernel | >= 5.5 < 5.9.9 | 5.9.9 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-36789: In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a
osv·2025-04-17·CVSS 5.5
CVE-2020-36789 [MEDIUM] CVE-2020-36789: In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_release_head_state() might be triggered, under network congestion circumstances, together with the potential risk of a NULL pointer dereference. The root cause of this issue is the call to kfree_skb() instead of dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog(). This patch prevents the skb to be freed within the call to netif_rx() by incrementing its reference count with skb_get(). The skb is finally freed by one of the in-irq-context safe functions: dev_consume_skb_any() or dev_kfree_skb_a
GHSA
GHSA-5974-c6r6-2pv9: In the Linux kernel, the following vulnerability has been resolved:
can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
If
ghsa_unreviewed·2025-04-17
CVE-2020-36789 [MEDIUM] CWE-476 GHSA-5974-c6r6-2pv9: In the Linux kernel, the following vulnerability has been resolved:
can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
If
In the Linux kernel, the following vulnerability has been resolved:
can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but
not always, the case), the 'WARN_ON(in_irq)' in
net/core/skbuff.c#skb_release_head_state() might be triggered, under network
congestion circumstances, together with the potential risk of a NULL pointer
dereference.
The root cause of this issue is the call to kfree_skb() instead of
dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog().
This patch prevents the skb to be freed within the call to netif_rx() by
incrementing its reference count with skb_get(). The skb is finally freed by
one of the in-irq-context safe functions: dev_consume_skb_any() or
dev_kfree_s
Red Hat
kernel: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
vendor_redhat·2025-04-17·CVSS 5.5
CVE-2020-36789 [MEDIUM] CWE-476 kernel: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
kernel: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
In the Linux kernel, the following vulnerability has been resolved:
can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context
If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but
not always, the case), the 'WARN_ON(in_irq)' in
net/core/skbuff.c#skb_release_head_state() might be triggered, under network
congestion circumstances, together with the potential risk of a NULL pointer
dereference.
The root cause of this issue is the call to kfree_skb() instead of
dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog().
This patch prevents the skb to be freed within the call to netif_rx() by
incrementing its reference count with skb_get(). The skb is finally free
Debian
CVE-2020-36789: linux - In the Linux kernel, the following vulnerability has been resolved: can: dev: c...
vendor_debian·2020·CVSS 5.5
CVE-2020-36789 [MEDIUM] CVE-2020-36789: linux - In the Linux kernel, the following vulnerability has been resolved: can: dev: c...
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_release_head_state() might be triggered, under network congestion circumstances, together with the potential risk of a NULL pointer dereference. The root cause of this issue is the call to kfree_skb() instead of dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog(). This patch prevents the skb to be freed within the call to netif_rx() by incrementing its reference count with skb_get(). The skb is finally freed by one of the in-irq-context safe functions: dev_consume_skb_any() or dev_kfree_skb_a
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2283f79b22684d2812e5c76fc2280aae00390365https://git.kernel.org/stable/c/248b71ce92d4f3a574b2537f9838f48e892618f4https://git.kernel.org/stable/c/3a922a85701939624484e7f2fd07d32beed00d25https://git.kernel.org/stable/c/451187b20431924d13fcfecc500d7cd2d9951bachttps://git.kernel.org/stable/c/7e4cf2ec0ca236c3e5f904239cec6efe1f3baf22https://git.kernel.org/stable/c/87530b557affe01c764de32dbeb58cdf47234574https://git.kernel.org/stable/c/ab46748bf98864f9c3f5559060bf8caf9df2b41e
2025-04-17
Published