PT-2020-7004 · Linux+1 · Linux Kernel+1

Published

2020-12-21

·

Updated

2024-12-11

·

CVE-2020-36787

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel's media subsystem, specifically the Aspeed video driver. It introduces improper reset on the Video Engine hardware, causing unexpected DMA memory transfers that can corrupt memory regions in random and sporadic patterns. This issue is observed very rarely on some specific AST2500 SoCs but causes a critical kernel panic, making it extremely hard to debug. The problem occurs even when the video engine is not actively used because udevd turns on the video engine hardware for a short time to make a query in every boot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-00833
CVE-2020-36787

Affected Products

Astra Linux
Linux Kernel