PT-2020-6861 · Linux+5 · Linux Kernel+5
Published
2020-05-01
·
Updated
2025-02-21
·
CVE-2020-36691
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.8
Description
The issue is related to uncontrolled recursion in the lib/nlattr.c component of the Linux kernel. This can be exploited by attackers to cause a denial of service via a nested Netlink policy with a back reference. The vulnerability allows attackers to cause a denial of service (unbounded recursion).
Recommendations
For Linux kernel versions prior to 5.8, update to version 5.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the lib/nlattr.c component to minimize the risk of exploitation. Avoid using nested Netlink policies with back references in the affected API endpoints until the issue is resolved.
Fix
DoS
Uncontrolled Recursion
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu