SB20240603185 - Reachable assertion in Linux kernel clk driver
Published: June 3, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Reachable assertion (CVE-ID: CVE-2020-36787)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to reachable assertion within the aspeed_video_off(), aspeed_video_on() and aspeed_video_probe() functions in drivers/media/platform/aspeed-video.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1dc1d30ac101bb8335d9852de2107af60c2580e7
- https://git.kernel.org/stable/c/a59d01384c80a8a4392665802df57c3df20055f5
- https://git.kernel.org/stable/c/2964c37563e86cfdc439f217eb3c5a69adfdba6a
- https://git.kernel.org/stable/c/75321dc8aebe3f30eff226028fe6da340fe0bf02
- https://git.kernel.org/stable/c/3536169f8531c2c5b153921dc7d1ac9fd570cda7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.37
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.21
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.119