CVE-2020-36785

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
28/02/2024
Last modified:
06/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs()<br /> <br /> The "s3a_buf" is freed along with all the other items on the<br /> "asd-&gt;s3a_stats" list. It leads to a double free and a use after free.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.8 (including) 5.10.37 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.11.21 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.12 (including) 5.12.4 (excluding)