Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8835

31
FAUCET Score

CVE-2020-8835 is a high-severity vulnerability in the Linux kernel (versions 5.5.0+, 5.4.7+) affecting the eBPF verifier, leading to out-of-bounds memory reads and writes. This flaw allows a local, low-privileged attacker to achieve privilege escalation with high impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, it has a high EPSS score and has garnered significant community discussion and media coverage, including its use in a Pwn2Own competition. No public exploit code is currently available in common frameworks like Metasploit or ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.4.7, < 5.4.29CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5.0, < 5.5.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.6, < 5.6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.01%
Probability of exploitation in next 30 days
EPSS Percentile
92.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0601 is in the 99th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

denopatch availablevia llm_extracted
Fixed in: latest patch version
View patch
invoiceplanepatch availablevia llm_extracted
Fixed in: latest patch version
View patch
pjsippatch availablevia llm_extracted
View patch

Vendor Advisories (5)

linuxCVE-2020-8835HIGH

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

Apr 2, 2020
redhatCVE-2020-8835Important

kernel: out-of-bounds read/write in the bpf verifier

Mar 30, 2020
pjsipllm-pjsip-cd2a540d67852918HIGH

Linux Kernel Container Escape Vulnerability

Jan 1, 2020
invoiceplanellm-invoiceplane-2b4315ec6c08e5fcHIGH

A vulnerability was recently discovered in the Linux kernel, described in CVE-2020-8835, allowing container escape to obtain root privileges on the host node.

denollm-deno-63d0e40ba0802ed2HIGH

Linux Kernel Container Escape Vulnerability

References

git.kernel.org / pub/scm/linux/kernel/git/netdev/net-next.git/commit
PatchVendor Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/F7OONYGMSYBEFHLHZJK3GOI5Z553G4LD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TF4PQZBEPNXDSK5DOBMW54OCLP25FTCD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YXBWSHZ6DJIZVXKXGZPK6QPFCY7VKZEG
lore.kernel.org / bpf/20200330160324.15259-1-daniel%40iogearbox.net/T
security.netapp.com / advisory/ntap-20200430-0004
Third Party Advisory
usn.ubuntu.com / 4313-1
Third Party Advisory
usn.ubuntu.com / usn/usn-4313-1
Third Party Advisory
openwall.com / lists/oss-security/2020/03/30/3
Mailing ListPatchThird Party Advisory
thezdi.com / blog/2020/3/19/pwn2own-2020-day-one-results
Third Party Advisory
openwall.com / lists/oss-security/2021/07/20/1
ExploitMailing ListThird Party Advisory