CVE-2020-8835

Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 02 Apr 2020, 18:00
Last modified:17 Sept 2024, 02:15

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
23.27% HIGH
23% probability -1.82%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

02 Apr 2020, 18:00
Published
Vulnerability first disclosed
17 Sept 2024, 02:15
Last Modified
Vulnerability information updated

Description

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 23.27% Percentile: 96%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • canonicalubuntu_linux

    18.04 | 19.10

  • fedoraprojectfedora

    30 | 31 | 32

  • linux kernellinux kernel

    ≥ 5.6-stable, < 5.6.1 | ≥ 5.5-stable, < 5.5.14 | ≥ 5.4.7, < 5.4-stable*

  • linuxlinux_kernel

    ≥ 5.4.7, < 5.4.29 | ≥ 5.5.0, < 5.5.14 | ≥ 5.6, < 5.6.1

  • netapp8300_firmware

    na

  • netapp8700_firmware

    na

  • netappa220_firmware

    na

  • netappa320_firmware

    na

  • netappa400_firmware

    na

  • netappa700s_firmware

    na

  • netappa800_firmware

    na

  • netappc190_firmware

    na

  • netappcloud_backup

    na

  • netappfas2720_firmware

    na

  • netappfas2750_firmware

    na

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph610c_firmware

    na

  • netapph610s_firmware

    na

  • netapph615c_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • netapphci_management_node

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

References (12)