Severity
7.8HIGHNVD
EPSS
23.3%
top 4.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateSep 24

Description

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel5.4.75.4.29+2
CVEListV5linux_kernel/linux_kernel5.6-stable5.6.1+2
Debianlinux/linux_kernel< 5.5.13-2+3

Also affects: Ubuntu Linux 18.04, 19.10, Fedora 30, 31, 32

Patches

🔴Vulnerability Details

3
GHSA
GHSA-774r-wvx9-mm68: In the Linux kernel 52022-05-24
CVEList
Linux kernel bpf verifier vulnerability2020-04-02
OSV
CVE-2020-8835: In the Linux kernel 52020-04-02

📋Vendor Advisories

3
Red Hat
kernel: out-of-bounds read/write in the bpf verifier2020-03-30
Ubuntu
Linux kernel vulnerability2020-03-30
Debian
CVE-2020-8835: linux - In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) di...2020

📄Research Papers

1
arXiv
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities2024-09-24

💬Community

3
Bugzilla
CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier [fedora-all]2020-03-30
Bugzilla
CVE-2020-8835 kernel: out-of-bounds read/write in the bpf verifier2020-03-26
Bugzilla
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution2020-03-24