PT-2025-17216 · Linux+2 · Linux Kernel+2

Published

2025-04-17

·

Updated

2025-05-21

·

CVE-2020-36789

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the CAN network stack. The issue occurs when a driver calls can get echo skb() during a hardware IRQ, potentially triggering a warning and risking a NULL pointer dereference due to the call to kfree skb() instead of dev kfree skb irq(). The root cause is the incorrect freeing of a socket buffer (skb) within the netif rx() call. The patch prevents this by incrementing the reference count of the skb and freeing it using dev consume skb any() or dev kfree skb any(). This issue was previously reported in 2017 but the proposed patch was not accepted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36789
OESA-2025-1465
OPENSUSE-SU-2025_01633-1
SUSE-SU-2025:01600-1
SUSE-SU-2025:01633-1
SUSE-SU-2025:1574-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01633-1

Affected Products

Astra Linux
Linux Kernel
Suse