cbcvebase.
CVE-2020-36788
published 2024-05-21

CVE-2020-36788: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: avoid a use-after-free when BO init fails nouveau_bo_init() is backed by…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: avoid a use-after-free when BO init fails nouveau_bo_init() is backed by ttm_bo_init() and ferries its return code back to the caller. On failures, ttm_bo_init() invokes the provided destructor which should de-initialize and free the memory. Thus, when nouveau_bo_init() returns an error the gem object has already been released and the memory freed by nouveau_bo_del_ttm().

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.12-1 (bookworm)linux 5.14.12-1 (bookworm)
linuxlinux
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < f86e19d918a85492ad1a01fcdc0ad5ecbdac6f96f86e19d918a85492ad1a01fcdc0ad5ecbdac6f96
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 548f2ff8ea5e0ce767ae3418d1ec5308990be87d548f2ff8ea5e0ce767ae3418d1ec5308990be87d
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < bcf34aa5082ee2343574bc3f4d1c126030913e54bcf34aa5082ee2343574bc3f4d1c126030913e54
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 5.11 < 5.14.125.14.12
linuxlinux_kernel>= 5.4 < 5.10.735.10.73

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.