Red Hat addressed CVE-2020-36516, a moderate-severity Linux kernel TCP/IP flaw that can let an off-path attacker inject data into an active TCP session or terminate it. The issue arises from interactions between mixed and hash-based IPID assignment, enabling packet spoofing through IP fragmentation and IPID collisions; successful exploitation requires a complex scenario and is considered more likely on a local network. Red Hat assigned a CVSS v3.1 score of 5.9, while upstream Linux fixed the vulnerability in kernel 5.17-rc2.
The fix was delivered for supported RHEL 8 and RHEL 9 kernel and real-time kernel packages, including through RHSA-2024:2674 for RHEL 8.6 extended-support channels. That advisory also remediates CVE-2024-26586 in the mlxsw Spectrum ACL TCAM component and applies across x86_64, s390x, ppc64le, and aarch64 offerings. Organizations should install the applicable kernel errata and reboot affected systems; Red Hat lists no qualifying mitigation, and RHEL 6 and RHEL 7 are outside support scope.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2022:7444 for RHEL 8 kernel-rt and RHSA-2022:7683 for the RHEL 8 kernel, addressing CVE-2020-36516.
Marian Rehak reported Red Hat bug 2059928 to track CVE-2020-36516, a Linux kernel IPID-assignment issue that could permit off-path TCP data injection or session termination.
Red Hat published RHSA-2024:2674 for RHEL 8.6 extended-support channels. The kernel update, version 4.18.0-372.102.1.el8_6, addressed CVE-2020-36516 and CVE-2024-26586.
Red Hat closed bug 2059928, its tracking record for CVE-2020-36516.
Red Hat released RHSA-2022:7933 for RHEL 9 kernel-rt and RHSA-2022:8267 for the RHEL 9 kernel, addressing CVE-2020-36516.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.