CVE-2020-36691: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbounded recursion) via a nested Netlink policy with a back reference.

Affected products

  • Linux Linux Kernel: before 5.8 (fixed in 5.8)

Published 2023-03-24. Last modified 2026-06-17.