CVE-2020-8835 is a Linux kernel eBPF verifier flaw in which register bounds for 32-bit operations were not restricted correctly. A crafted eBPF program can cause the verifier to incorrectly validate operations that access memory outside intended bounds, resulting in out-of-bounds kernel-memory reads and writes. The issue affects Linux kernel releases 5.5.0 and later before 5.5.14 and the Linux 5.4 stable series from 5.4.7 before 5.4.29; it was corrected in 5.6.1, 5.5.14, and 5.4.29.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit for CVE-2020-8835, targeting the Linux kernel (versions 5.5.0 and newer, and 5.4.x from v5.4.7 to v5.4.29). The exploit leverages a flaw in the BPF verifier that allows out-of-bounds kernel memory access via crafted BPF programs. The main file, 'exploit.c', is a C program that constructs and loads a malicious BPF program, attaches it to a socket, and manipulates kernel memory to locate and overwrite the current process's credentials structure, ultimately granting root privileges. Upon success, it spawns a root shell by invoking '/bin/sh'. The README provides compilation instructions, affected versions, and mitigation steps (disabling unprivileged BPF via sysctl). The exploit requires local access and the ability to load BPF programs (i.e., unprivileged BPF must not be disabled). No network endpoints are involved; the attack vector is purely local. The code is operational and provides a working privilege escalation payload.
This repository contains a working exploit for CVE-2020-8835, a privilege escalation vulnerability in the Linux kernel's eBPF implementation. The exploit is implemented in C and is split into two main variants: one under 'hijack_prctl/exp/hijack_prctl.c' and another under 'vdso/exp/last.c'. Both leverage eBPF programs to manipulate kernel memory, leak kernel addresses, and ultimately overwrite sensitive kernel structures (such as modprobe_path) to execute arbitrary commands as root. The exploit includes helper scripts and QEMU configurations to emulate a vulnerable environment for testing. The payload changes permissions on a target file (/flag) or spawns a shell, demonstrating successful privilege escalation. The attack vector is local, requiring the attacker to execute code on the target system. The repository is well-structured for research and operational exploitation, providing both the exploit code and the necessary environment setup scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously disclosed Linux kernel privilege-escalation vulnerability involving improper eBPF program verification, mentioned only as the source of techniques reused in the CVE-2021-33909 exploit.
An earlier Linux kernel eBPF verifier vulnerability referenced for background and exploitation methodology comparison.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.