U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NOTICE UPDATED - April, 25th 2024

NIST has updated the NVD program announcement page with additional information regarding recent concerns and the temporary delays in enrichment efforts.

CVE-2020-36777 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_free() dvb_media_device_free() is leaking memory. Free `dvbdev->adapter->conn` before setting it to NULL, as documented in include/media/media-device.h: "The media_entity instance itself must be freed explicitly by the driver if required."


Severity



CVSS 3.x Severity and Metrics:

NIST CVSS score
NIST: NVD
Base Score:  5.5 MEDIUM
Vector:  CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H


NVD Analysts use publicly available information to associate vector strings and CVSS scores. We also display any CVSS information provided within the CVE List from the CNA.

Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. The CNA has not provided a score within the CVE List.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
https://git.kernel.org/stable/c/06854b943e0571ccbd7ad0a529babed1a98ff275 Patch 
https://git.kernel.org/stable/c/32168ca1f123316848fffb85d059860adf3c409f Patch 
https://git.kernel.org/stable/c/43263fd43083e412311fa764cd04a727b0c6a749 Patch 
https://git.kernel.org/stable/c/9185b3b1c143b8da409c19ac5a785aa18d67a81b Patch 
https://git.kernel.org/stable/c/9ad15e214fcd73694ea51967d86055f47b802066 Patch 
https://git.kernel.org/stable/c/bf9a40ae8d722f281a2721779595d6df1c33a0bf Patch 
https://git.kernel.org/stable/c/cd89f79be5d553c78202f686e8e4caa5fbe94e98 Patch 
https://git.kernel.org/stable/c/cede24d13be6c2a62be6d7ceea63c2719b0cfa82 Patch 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-401 Missing Release of Memory after Effective Lifetime cwe source acceptance level NIST  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

2 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2020-36777
NVD Published Date:
02/27/2024
NVD Last Modified:
04/10/2024
Source:
kernel.org