CVE-2020-36158: Debian Linux
Medium severity, CVSS 6.7. EPSS: 2.3% chance of exploitation in the next 30 days.
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 33 only
- Linux Linux Kernel: from 3.0, before 4.4.250 (fixed in 4.4.250); from 4.5, before 4.9.250 (fixed in 4.9.250); from 4.10, before 4.14.214 (fixed in 4.14.214); from 4.15, before 4.19.166 (fixed in 4.19.166); from 4.20, before 5.4.88 (fixed in 5.4.88); from 5.5, before 5.10.6 (fixed in 5.10.6)
- Netapp Cloud Backup: affected versions not specified
- Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified
Published 2021-01-05. Last modified 2026-06-17.