CVE-2020-36322: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Linux Linux Kernel: before 5.10.6 (fixed in 5.10.6)
  • Starwindsoftware Starwind Virtual San: version 8 only

Published 2021-04-14. Last modified 2026-06-17.