CVE-2020-36791
published 2025-05-07CVE-2020-36791: In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567…
PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.17%
6.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
net_sched: keep alloc_hash updated after hash allocation
In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex")
I moved cp->hash calculation before the first
tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched.
This difference could lead to another out of bound access.
cp->alloc_hash should always be the size allocated, we should
update it after this tcindex_alloc_perfect_hash().
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.5.17-1 (bookworm) | linux 5.5.17-1 (bookworm) |
| linux | linux | >= 2c66ff8d08f81bcf8e8cb22e31e39c051b15336a < bd3ee8fb6371b45c71c9345cc359b94da2ddefa9 | bd3ee8fb6371b45c71c9345cc359b94da2ddefa9 |
| linux | linux | >= 4.14.171 < 4.14.175 | 4.14.175 |
| linux | linux | >= 4.19.103 < 4.19.114 | 4.19.114 |
| linux | linux | >= 4.4.214 < 4.4.218 | 4.4.218 |
| linux | linux | >= 4.9.214 < 4.9.218 | 4.9.218 |
| linux | linux | >= 478c4b2ffd44e5186c7e22ae7c38a86a5b9cfde5 < 557d015ffb27b672e24e6ad141fd887783871dc2 | 557d015ffb27b672e24e6ad141fd887783871dc2 |
| linux | linux | >= 5.4.19 < 5.4.29 | 5.4.29 |
| linux | linux | >= 5.5.3 < 5.5.14 | 5.5.14 |
| linux | linux | >= 599be01ee567b61f4471ee8078870847d0a11e8e < 0d1c3530e1bd38382edef72591b78e877e0edcd3 | 0d1c3530e1bd38382edef72591b78e877e0edcd3 |
| linux | linux | >= 6cb448ee493c8a514c9afa0c346f3f5b3227de85 < 9f8b6c44be178c2498a00b270872a6e30e7c8266 | 9f8b6c44be178c2498a00b270872a6e30e7c8266 |
| linux | linux | >= 73c29d2f6f8ae731b1e09051b69ed3ba2319482b < d6cdc5bb19b595486fb2e6661e5138d73a57f454 | d6cdc5bb19b595486fb2e6661e5138d73a57f454 |
| linux | linux | >= b974ac51f5834a729de252fc5c1c9de9efd79b45 < c4453d2833671e3a9f6bd52f0f581056c3736386 | c4453d2833671e3a9f6bd52f0f581056c3736386 |
| linux | linux | >= dd8142a6fa5270783d415292ec8169f4ea2a5468 < d23faf32e577922b6da20bf3740625c1105381bf | d23faf32e577922b6da20bf3740625c1105381bf |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-36791: In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("
osv·2025-05-07·CVSS 7.1
CVE-2020-36791 [HIGH] CVE-2020-36791: In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("
In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched. This difference could lead to another out of bound access. cp->alloc_hash should always be the size allocated, we should update it after this tcindex_alloc_perfect_hash().
GHSA
GHSA-5pxm-fr3g-jf32: In the Linux kernel, the following vulnerability has been resolved:
net_sched: keep alloc_hash updated after hash allocation
In commit 599be01ee567
ghsa_unreviewed·2025-05-07
CVE-2020-36791 [HIGH] CWE-125 GHSA-5pxm-fr3g-jf32: In the Linux kernel, the following vulnerability has been resolved:
net_sched: keep alloc_hash updated after hash allocation
In commit 599be01ee567
In the Linux kernel, the following vulnerability has been resolved:
net_sched: keep alloc_hash updated after hash allocation
In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex")
I moved cp->hash calculation before the first
tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched.
This difference could lead to another out of bound access.
cp->alloc_hash should always be the size allocated, we should
update it after this tcindex_alloc_perfect_hash().
Red Hat
kernel: net_sched: keep alloc_hash updated after hash allocation
vendor_redhat·2025-05-07·CVSS 7.1
CVE-2020-36791 [HIGH] kernel: net_sched: keep alloc_hash updated after hash allocation
kernel: net_sched: keep alloc_hash updated after hash allocation
In the Linux kernel, the following vulnerability has been resolved:
net_sched: keep alloc_hash updated after hash allocation
In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex")
I moved cp->hash calculation before the first
tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched.
This difference could lead to another out of bound access.
cp->alloc_hash should always be the size allocated, we should
update it after this tcindex_alloc_perfect_hash().
A possible out-of-bounds access was found in the Linux kernel in net_sched. This may result in unstable availability.
Statement: Red Hat has stack protection mechanisms in place, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smash
Debian
CVE-2020-36791: linux - In the Linux kernel, the following vulnerability has been resolved: net_sched: ...
vendor_debian·2020·CVSS 7.1
CVE-2020-36791 [HIGH] CVE-2020-36791: linux - In the Linux kernel, the following vulnerability has been resolved: net_sched: ...
In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched. This difference could lead to another out of bound access. cp->alloc_hash should always be the size allocated, we should update it after this tcindex_alloc_perfect_hash().
Scope: local
bookworm: resolved (fixed in 5.5.17-1)
bullseye: resolved (fixed in 5.5.17-1)
forky: resolved (fixed in 5.5.17-1)
sid: resolved (fixed in 5.5.17-1)
trixie: resolved (fixed in 5.5.17-1)
No detection rules found.
No public exploits indexed.
https://blog.cdthoughts.ch/2021/03/16/syzbot-bug.htmlhttps://git.kernel.org/stable/c/0d1c3530e1bd38382edef72591b78e877e0edcd3https://git.kernel.org/stable/c/557d015ffb27b672e24e6ad141fd887783871dc2https://git.kernel.org/stable/c/9f8b6c44be178c2498a00b270872a6e30e7c8266https://git.kernel.org/stable/c/bd3ee8fb6371b45c71c9345cc359b94da2ddefa9https://git.kernel.org/stable/c/c4453d2833671e3a9f6bd52f0f581056c3736386https://git.kernel.org/stable/c/d23faf32e577922b6da20bf3740625c1105381bfhttps://git.kernel.org/stable/c/d6cdc5bb19b595486fb2e6661e5138d73a57f454https://syzkaller.appspot.com/bug?id=ea260693da894e7b078d18fca2c9c0a19b457534
2025-05-07
Published