CVE-2020-8835: exploitation status and patch state

CVE-2020-8835 · CVSS 7.8 HIGH · EPSS 6%

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

Is CVE-2020-8835 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2020-8835

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-15.