CVE-2020-36780 is a reference leak vulnerability in the Linux kernel's I2C driver for Spreadtrum devices, specifically within the sprd_i2c_master_xfer() and sprd_i2c_remove() functions. The issue arises when pm_runtime_get_sync fails, incrementing the PM reference count without a corresponding decrement, leading to a resource leak. This vulnerability has a CVSS score of 4.7 (Medium), indicating a low-privilege local attack with high impact on availability, but requiring high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14, < 5.4.119CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.11.21CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.12, < 5.12.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.