{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2020-36791","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-26T17:07:27.435Z","datePublished":"2025-05-07T13:17:33.882Z","dateUpdated":"2026-08-05T08:44:33.087Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:44:33.087Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: keep alloc_hash updated after hash allocation\n\nIn commit 599be01ee567 (\"net_sched: fix an OOB access in cls_tcindex\")\nI moved cp->hash calculation before the first\ntcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched.\nThis difference could lead to another out of bound access.\n\ncp->alloc_hash should always be the size allocated, we should\nupdate it after this tcindex_alloc_perfect_hash()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is triggered through the tc filter netlink configuration path (RTM_NEWTFILTER → tc_new_tfilter → tcindex_change → tcindex_set_parms), not by processing network packets. Exploitation requires local netlink/syscall access to configure cls_tcindex.\nAC:L - An attacker fully controls both the old and new hash sizes and the filter handle via netlink attributes, so shrinking a perfect hash while using a handle past the newly allocated size reliably produces the OOB access with no race or external conditions.\nPR:L - tc_new_tfilter requires CAP_NET_ADMIN checked with netlink_ns_capable against the network namespace's user_ns, which an unprivileged user can obtain via user namespaces (unshare -Urn) without real root in the init namespace.\nUI:N - The attacker creates and modifies their own tcindex filters in a network namespace they control; no victim action is required.\nS:U - Impact is confined to the host kernel privilege boundary (local memory corruption / privilege escalation) and does not cross VM, IOMMU, or other distinct security authorities.\nC:H - Stale alloc_hash allows OOB reads through tcindex_get/tcindex_lookup (perfect + handle beyond the allocated array), and the heap OOB can be leveraged for arbitrary kernel memory disclosure.\nI:H - tcindex_set_parms does r = cp->perfect + handle then writes result/exts into that slot; with handle past the newly allocated hash this is a controlled heap out-of-bounds write enabling memory corruption and control-flow hijacking.\nA:H - The out-of-bounds access was caught by syzbot as a kernel memory-safety failure and can produce oops/panic or heap corruption leading to a crash even without full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sched/cls_tcindex.c"],"versions":[{"version":"73c29d2f6f8ae731b1e09051b69ed3ba2319482b","lessThan":"d6cdc5bb19b595486fb2e6661e5138d73a57f454","status":"affected","versionType":"git"},{"version":"b974ac51f5834a729de252fc5c1c9de9efd79b45","lessThan":"c4453d2833671e3a9f6bd52f0f581056c3736386","status":"affected","versionType":"git"},{"version":"6cb448ee493c8a514c9afa0c346f3f5b3227de85","lessThan":"9f8b6c44be178c2498a00b270872a6e30e7c8266","status":"affected","versionType":"git"},{"version":"478c4b2ffd44e5186c7e22ae7c38a86a5b9cfde5","lessThan":"557d015ffb27b672e24e6ad141fd887783871dc2","status":"affected","versionType":"git"},{"version":"dd8142a6fa5270783d415292ec8169f4ea2a5468","lessThan":"d23faf32e577922b6da20bf3740625c1105381bf","status":"affected","versionType":"git"},{"version":"2c66ff8d08f81bcf8e8cb22e31e39c051b15336a","lessThan":"bd3ee8fb6371b45c71c9345cc359b94da2ddefa9","status":"affected","versionType":"git"},{"version":"599be01ee567b61f4471ee8078870847d0a11e8e","lessThan":"0d1c3530e1bd38382edef72591b78e877e0edcd3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sched/cls_tcindex.c"],"versions":[{"version":"4.4.214","lessThan":"4.4.218","status":"affected","versionType":"semver"},{"version":"4.9.214","lessThan":"4.9.218","status":"affected","versionType":"semver"},{"version":"4.14.171","lessThan":"4.14.175","status":"affected","versionType":"semver"},{"version":"4.19.103","lessThan":"4.19.114","status":"affected","versionType":"semver"},{"version":"5.4.19","lessThan":"5.4.29","status":"affected","versionType":"semver"},{"version":"5.5.3","lessThan":"5.5.14","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.214","versionEndExcluding":"4.4.218"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.214","versionEndExcluding":"4.9.218"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.171","versionEndExcluding":"4.14.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.103","versionEndExcluding":"4.19.114"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.19","versionEndExcluding":"5.4.29"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.3","versionEndExcluding":"5.5.14"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d6cdc5bb19b595486fb2e6661e5138d73a57f454"},{"url":"https://git.kernel.org/stable/c/c4453d2833671e3a9f6bd52f0f581056c3736386"},{"url":"https://git.kernel.org/stable/c/9f8b6c44be178c2498a00b270872a6e30e7c8266"},{"url":"https://git.kernel.org/stable/c/557d015ffb27b672e24e6ad141fd887783871dc2"},{"url":"https://git.kernel.org/stable/c/d23faf32e577922b6da20bf3740625c1105381bf"},{"url":"https://git.kernel.org/stable/c/bd3ee8fb6371b45c71c9345cc359b94da2ddefa9"},{"url":"https://git.kernel.org/stable/c/0d1c3530e1bd38382edef72591b78e877e0edcd3"},{"url":"https://syzkaller.appspot.com/bug?id=ea260693da894e7b078d18fca2c9c0a19b457534"},{"url":"https://blog.cdthoughts.ch/2021/03/16/syzbot-bug.html"}],"title":"net_sched: keep alloc_hash updated after hash allocation","x_generator":{"engine":"bippy-1.2.0"}}}}