CVE-2020-36779: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: i2c: stm32f7: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected to be incremented on return in these stm32f7_i2c_xx serious functions. However, pm_runtime_get_sync will increment the PM reference count even failed. Forgetting to putting operation will result in a reference leak here. Replace it with pm_runtime_resume_and_get to keep usage counter balanced.

Affected products

  • Linux Linux Kernel: from 5.6, before 5.10.37 (fixed in 5.10.37); from 5.11, before 5.11.21 (fixed in 5.11.21); from 5.12, before 5.12.4 (fixed in 5.12.4)

Published 2024-02-28. Last modified 2026-06-17.