SB20240530140 - Memory leak in Linux kernel atomisp i2c driver
Published: May 30, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2020-36786)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the lm3554_probe() function in drivers/staging/media/atomisp/i2c/atomisp-lm3554.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/cc4cc2fb5aaf9adb83c02211eb13b16cfcb7ba64
- https://git.kernel.org/stable/c/4f0f37d03cde8f4341df8454f9b40a67fda94a33
- https://git.kernel.org/stable/c/27d2eab69f7da8e94e4751ac5c6d22d809275484
- https://git.kernel.org/stable/c/6045b01dd0e3cd3759eafe7f290ed04c957500b1
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.37
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.21
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13