HIGH · 7.8

CVE-2020-8835

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel m...

Vulnerability Description

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 5.4.7, < 5.4.29
FedoraprojectFedora30
CanonicalUbuntu Linux18.04
NetappCloud Backup-
NetappHci Management Node-
NetappSolidfire-
NetappSteelstore Cloud Integrated Storage-
NetappA700S Firmware-
NetappA700S-
Netapp8300 Firmware-
Netapp8300-
Netapp8700 Firmware-
Netapp8700-
NetappA400 Firmware-
NetappA400-
NetappA320 Firmware-
NetappA320-
NetappC190 Firmware-
NetappC190-
NetappA220 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8835?

CVE-2020-8835 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel m...

How severe is CVE-2020-8835?

CVE-2020-8835 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8835?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Canonical Ubuntu Linux, Netapp Cloud Backup, Netapp Hci Management Node.