Bug 2266958 (CVE-2020-36787)
| Summary: | CVE-2020-36787 kernel: media: aspeed: fix clock handling logic | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Avinash Hanwate <ahanwate> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | acaringi, allarkin, aquini, bhu, chwhite, cye, cyin, dbohanno, debarbos, dfreiber, drow, dvlasenk, esandeen, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jforbes, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lzampier, mleitner, mmilgram, mstowell, nmurray, ptalbert, rparrazo, rrobaina, rvrbovsk, scweaver, sidakwo, sukulkar, tglozar, vkumar, wcosta, williams, wmealing, ycote, ykopkova, zhijwang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | kernel 5.4.119, kernel 5.10.37, kernel 5.11.21, kernel 5.12.4, kernel 5.13 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A clock handling logic flaw was found in the Linux kernel, which introduces an improper reset on the Video Engine hardware and may generate unexpected DMA memory transfers that can corrupt the memory region in random and sporadic ways.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2266959 | ||
| Bug Blocks: | 2266960 | ||
|
Description
Avinash Hanwate
2024-02-29 09:41:22 UTC
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2266959] This was fixed for Fedora with the 5.12.4 stable kernel updates. The result of automatic check (that is developed by Alexander Larkin) for this CVE-2020-36787 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built). |