cbcvebase.
CVE-2020-36791
published 2025-05-07

CVE-2020-36791: In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.17%
6.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched. This difference could lead to another out of bound access. cp->alloc_hash should always be the size allocated, we should update it after this tcindex_alloc_perfect_hash().

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.5.17-1 (bookworm)linux 5.5.17-1 (bookworm)
linuxlinux>= 2c66ff8d08f81bcf8e8cb22e31e39c051b15336a < bd3ee8fb6371b45c71c9345cc359b94da2ddefa9bd3ee8fb6371b45c71c9345cc359b94da2ddefa9
linuxlinux>= 4.14.171 < 4.14.1754.14.175
linuxlinux>= 4.19.103 < 4.19.1144.19.114
linuxlinux>= 4.4.214 < 4.4.2184.4.218
linuxlinux>= 4.9.214 < 4.9.2184.9.218
linuxlinux>= 478c4b2ffd44e5186c7e22ae7c38a86a5b9cfde5 < 557d015ffb27b672e24e6ad141fd887783871dc2557d015ffb27b672e24e6ad141fd887783871dc2
linuxlinux>= 5.4.19 < 5.4.295.4.29
linuxlinux>= 5.5.3 < 5.5.145.5.14
linuxlinux>= 599be01ee567b61f4471ee8078870847d0a11e8e < 0d1c3530e1bd38382edef72591b78e877e0edcd30d1c3530e1bd38382edef72591b78e877e0edcd3
linuxlinux>= 6cb448ee493c8a514c9afa0c346f3f5b3227de85 < 9f8b6c44be178c2498a00b270872a6e30e7c82669f8b6c44be178c2498a00b270872a6e30e7c8266
linuxlinux>= 73c29d2f6f8ae731b1e09051b69ed3ba2319482b < d6cdc5bb19b595486fb2e6661e5138d73a57f454d6cdc5bb19b595486fb2e6661e5138d73a57f454
linuxlinux>= b974ac51f5834a729de252fc5c1c9de9efd79b45 < c4453d2833671e3a9f6bd52f0f581056c3736386c4453d2833671e3a9f6bd52f0f581056c3736386
linuxlinux>= dd8142a6fa5270783d415292ec8169f4ea2a5468 < d23faf32e577922b6da20bf3740625c1105381bfd23faf32e577922b6da20bf3740625c1105381bf
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.