First published: Mon Sep 18 2023(Updated: )
An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memory on specific hardware to unprivileged users, because of directly assigning log_addrs with a hole in the struct.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <5.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-36766.
The severity level of CVE-2020-36766 is low, with a severity value of 3.3.
The affected software is the Linux Kernel version up to 5.8.6.
CVE-2020-36766 is an issue in the Linux kernel where the `cec-api.c` file leaks one byte of kernel memory to unprivileged users on specific hardware.
To fix CVE-2020-36766, users should update their Linux Kernel to version 5.8.6 or above.