First published: Fri Mar 24 2023(Updated: )
An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbounded recursion) via a nested Netlink policy with a back reference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <5.8 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36691 is classified as a denial of service vulnerability due to unbounded recursion in the Linux kernel.
To fix CVE-2020-36691, upgrade the Linux kernel to version 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, or 6.12.12-1.
CVE-2020-36691 affects the Linux kernel versions before 5.8.
Yes, CVE-2020-36691 can be exploited by attackers to cause a denial of service remotely.
CVE-2020-36691 is a vulnerability in the Linux kernel and can potentially affect all distributions using affected versions.