PT-2020-6914 · Linux+1 · Linux Kernel+1

Published

2020-06-19

·

Updated

2023-11-02

·

CVE-2020-36766

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.8.6
Description An issue in the Linux kernel's drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on specific hardware to unprivileged users. This occurs because of directly assigning log addrs with a hole in the struct, which is related to improper handling of input data concerning the cec log addrs structure. Exploitation of this issue may allow an attacker to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.8.6, update to version 5.8.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable cec-api.c component until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05906
CVE-2020-36766
OESA-2023-1727
OESA-2023-1728
OPENSUSE-SU-2023_4347-1
SUSE-SU-2023:4030-1
SUSE-SU-2023:4031-1
SUSE-SU-2023:4032-1
SUSE-SU-2023:4033-1
SUSE-SU-2023:4095-1
SUSE-SU-2023:4142-1
SUSE-SU-2023:4347-1
SUSE-SU-2023_4030-1
SUSE-SU-2023_4031-1
SUSE-SU-2023_4032-1
SUSE-SU-2023_4033-1
SUSE-SU-2023_4095-1

Affected Products

Linux Kernel
Suse