UBUNTU-CVE-2020-36784
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-36784
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected to be incremented on return in functions cdns_i2c_master_xfer and cdns_reg_slave. However, pm_runtime_get_sync will increment pm usage counter even failed. Forgetting to putting operation will result in a reference leak here. Replace it with pm_runtime_resume_and_get to keep usage counter balanced.
References: https://ubuntu.com/security/CVE-2020-36784, https://git.kernel.org/linus/23ceb8462dc6f4b4decdb5536a7e5fc477cdf0b6, https://git.kernel.org/stable/c/30410519328c94367e561fd878e5f0d3a0303585, https://git.kernel.org/stable/c/d57ff04e0ed6f3be1682ae861ead33f879225e07, https://git.kernel.org/stable/c/a45fc41beed8e0fe31864619c34aa00797fb60c1, https://git.kernel.org/stable/c/23ceb8462dc6f4b4decdb5536a7e5fc477cdf0b6, https://www.cve.org/CVERecord?id=CVE-2020-36784
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
