CVE-2020-36322: Medium severity linux kernel vulnerability
A denial of service flaw was found in fusedogetattr in fs/fuse/dir.c in the kernel side of the FUSE filesystem in the Linux kernel. A local user could use this flaw to crash the system.
Other sources
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fusedogetattr() calls makebadinode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6. fusedogetattr() calls makebadinode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.
Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5d069dbe8aaf2a197142558b6fb2978189ba3454
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-36322?
CVE-2020-36322 has been classified as a denial of service vulnerability that can lead to system crashes.
How do I fix CVE-2020-36322?
To fix CVE-2020-36322, update the Linux kernel to versions 5.10.6 or later, or apply the relevant patches for your distribution.
Which versions of Linux are affected by CVE-2020-36322?
CVE-2020-36322 affects Linux kernel versions prior to 5.10.6, including specific versions of Red Hat and Debian kernels.
Can a local user exploit CVE-2020-36322?
Yes, a local user can exploit CVE-2020-36322 to crash the system and cause a denial of service.
Is CVE-2020-36322 fixed in the latest Linux kernels?
Yes, CVE-2020-36322 is resolved in Linux kernel versions 5.10.6 and higher.