CVE-2020-36158: High severity linux kernel vulnerability
Last updated 25 April 2025
Other sources
mwifiexcmd80211adhocstart in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
— Launchpad
mwifiexcmd80211adhocstart in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value.
Reference and upstream patch: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5c455c5ab332773464d02ba17015acdca198f03d
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36158?
CVE-2020-36158 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2020-36158?
To fix CVE-2020-36158, upgrade the Linux kernel to versions 5.10.223-1, 5.10.226-1, or a later version.
Which versions of the Linux kernel are affected by CVE-2020-36158?
CVE-2020-36158 affects multiple versions of the Linux kernel from 3.0 to 5.10.4.
What type of vulnerability is CVE-2020-36158?
CVE-2020-36158 is classified as a remote code execution vulnerability.
Who can be affected by CVE-2020-36158?
Users of the affected Linux kernel versions are at risk of exploitation from remote attackers.