VDB

CVE-2020-36788

CVE-2020-36788 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: avoid a use-after-free when BO init fails nouveau_bo_init() is backed by ttm_bo_init() and ferries its return code back to the caller. On failures, ttm_bo_init() invokes the provided destructor which should de-initialize and free the memory. Thus, when nouveau_bo_init() returns an error the gem object has already been released and the memory freed by nouveau_bo_del_ttm().

EPSS 0.02% · 3.8th percentile

Risk Scores

EPSS Score
0.02%
3.8th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-hwe-5.135.13.0-28.31~20.04.1, 5.13.0-30.33~20.04.1, 0
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-fips5.4.0-1076.85, 5.4.0-1100.110, 5.4.0-1101.111
Ubuntu:20.04:LTSlinux-gcp-5.13*, 5.13.0-1027.32~20.04.1, 5.13.0-1024.29~20.04.1
Ubuntu:18.04:LTSlinux-azure5.0.0-1032.34, 4.15.0-1009.9, 4.15.0-1012.12
Ubuntu:22.04:LTSlinux-nvidia-6.26.2.0-1012.12, 6.2.0-1011.11, 0
Ubuntu:22.04:LTSlinux-azure-5.195.19.0-1027.30~22.04.2, *, *
Ubuntu:18.04:LTSlinux-azure-5.35.3.0-1019.20~18.04.1, 5.3.0-1020.21~18.04.1, 5.3.0-1022.23~18.04.1
Ubuntu:Pro:20.04:LTSlinux-raspi5.4.0-1030.33, 5.4.0-1078.89, 5.4.0-1133.146
Ubuntu:22.04:LTSlinux-allwinner-5.195.19.0-1014.14~22.04.1, 5.19.0-1013.13~22.04.1, 5.19.0-1012.12~22.04.1
Ubuntu:20.04:LTSlinux-aws-5.115.11.0-1022.23~20.04.1, 5.11.0-1021.22~20.04.2, *
Ubuntu:20.04:LTSlinux-oracle-5.135.13.0-1030.35~20.04.1, 5.13.0-1033.39~20.04.1, 5.13.0-1036.43~20.04.1
Ubuntu:22.04:LTSlinux-hwe-5.195.19.0-38.39~22.04.1, *, 0
Ubuntu:20.04:LTSlinux-gke-5.150, 5.15.0-1011.14~20.04.1, 5.15.0-1014.17~20.04.1
Ubuntu:18.04:LTSlinux-gke-5.45.4.0-1051.54~18.04.1, *, *
Ubuntu:20.04:LTSlinux-hwe-5.85.8.0-31.33~20.04.1, 5.8.0-29.31~20.04.1, 5.8.0-28.30~20.04.1
Ubuntu:20.04:LTSlinux-oracle-5.85.8.0-1031.32~20.04.2, 5.8.0-1034.35~20.04.2, 5.8.0-1037.38~20.04.1
Ubuntu:Pro:20.04:LTSlinux5.4.0-216.236, 5.4.0-221.241, 5.4.0-189.209
Ubuntu:22.04:LTSlinux-riscv5.15.0-1026.30, 5.15.0-1023.27, 5.15.0-1022.26
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:Pro:18.04:LTSlinux-ibm-5.45.4.0-1059.64~18.04.1, *, *

…and 73 more

Timeline

  • May 21, 2024 CVE Published
  • May 22, 2024 EPSS Score
  • Jun 16, 2024 EPSS Score
  • Jul 9, 2024 EPSS Score
  • Aug 2, 2024 EPSS Score
  • Aug 26, 2024 EPSS Score
  • Sep 18, 2024 EPSS Score
  • Oct 12, 2024 EPSS Score
  • Nov 5, 2024 EPSS Score
  • Nov 29, 2024 EPSS Score
  • Dec 23, 2024 EPSS Score
  • Jan 16, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›