LiveActive security incident?Get immediate response
CVE Record

CVE-2020-36387: An issue was discovered in the Linux kernel before 5.8.2.

An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2020-36387 is a Linux kernel memory-safety bug in io_uring before kernel 5.8.2. A kernel use-after-free can threaten system stability and, depending on context, may create security impact. The supplied sources do not provide CVSS scoring, confirmed exploitation, or full product exposure details.

Executive priority

Treat as a patch-validation item with uncertain severity. Kernel memory-safety flaws can be material, but the supplied sources lack exploitation and scoring evidence. Prioritize based on kernel age, workload exposure, and vendor advisory coverage.

Technical view

The CVE describes a use-after-free in fs/io_uring.c involving io_async_task_func and ctx reference holding. The upstream Linux fix is identified as commit 6d816e088c35 and appears in the Linux 5.8.2 changelog. Syzkaller/SyzScope references indicate fuzzing-based kernel memory error evidence.

Likely exposure

Likely exposure is Linux systems using kernel versions before 5.8.2 where io_uring is present. The bundle does not enumerate distributions, appliances, or exact vendor product versions. NetApp published an advisory, but affected NetApp scope is not included here.

Exploitation context

The CVE is not listed as KEV in the provided bundle, and no supplied source states active exploitation. The public evidence points to kernel bug tracking and upstream correction, not confirmed in-the-wild exploitation.

Researcher notes

Evidence is limited to the CVE description, upstream changelog, syzkaller/SyzScope references, the fixing commit, and a NetApp advisory link. Do not infer exploitability, privilege requirements, or product impact beyond those sources without additional vendor data.

Mitigation direction

  • Upgrade to a vendor kernel containing the upstream fix or Linux 5.8.2 or later lineage.
  • Check operating system and appliance vendor advisories for backported fixes.
  • Prioritize internet-facing, multi-user, container-hosting, and untrusted-workload Linux systems.
  • Review NetApp advisory applicability if NetApp products are in scope.

Validation and detection

  • Inventory Linux kernel versions across servers, endpoints, containers hosts, and appliances.
  • Confirm whether vendor kernels backport commit 6d816e088c35 or equivalent fix.
  • Check whether io_uring is enabled or relevant to exposed workloads.
  • Record compensating controls only when vendor patching cannot occur promptly.
Prepared
Confidence
medium
Sources
7

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-36387 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
6Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.