CVE-2019-20636
published 2020-04-08CVE-2019-20636: In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.7th percentile
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.4.13-1 (bookworm) | linux 5.4.13-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.16.83 | 3.16.83 |
| linux | linux_kernel | >= 0 < 5.4.13-1 | 5.4.13-1 |
| linux | linux_kernel | >= 0 < 5.4.13-1 | 5.4.13-1 |
| linux | linux_kernel | >= 0 < 5.4.13-1 | 5.4.13-1 |
| linux | linux_kernel | >= 0 < 5.4.13-1 | 5.4.13-1 |
| linux | linux_kernel | >= 3.17 < 4.4.210 | 4.4.210 |
| linux | linux_kernel | >= 4.10 < 4.14.165 | 4.14.165 |
| linux | linux_kernel | >= 4.15 < 4.19.96 | 4.19.96 |
| linux | linux_kernel | >= 4.20 < 5.4.12 | 5.4.12 |
| linux | linux_kernel | >= 4.5 < 4.9.210 | 4.9.210 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2019-20636: Input driver
vendor_android·2020-07-01·CVSS 6.7
CVE-2019-20636 [MEDIUM] CVE-2019-20636: Input driver
Android Security Bulletin 2020-07-01
CVE: CVE-2019-20636
Severity: HIGH
Type: EoP
Component: Input driver
References: A-153715664
Upstream kernel
Red Hat
kernel: out-of-bounds write via crafted keycode table
vendor_redhat·2020-04-04·CVSS 6.7
CVE-2019-20636 [MEDIUM] CWE-787 kernel: out-of-bounds write via crafted keycode table
kernel: out-of-bounds write via crafted keycode table
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
An out-of-bounds write flaw was found in the Linux kernel. A crafted keycode table could be used by drivers/input/input.c to perform the out-of-bounds write. A local user with root access can insert garbage to this keycode table that can lead to out-of-bounds memory access. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This issue was rated as having Moderate impact because of the need of physical access or administrator privileges to trigger it.
Mitigation: Mitigation for this issue is
Debian
CVE-2019-20636: linux - In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds write...
vendor_debian·2019·CVSS 6.7
CVE-2019-20636 [MEDIUM] CVE-2019-20636: linux - In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds write...
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
Scope: local
bookworm: resolved (fixed in 5.4.13-1)
bullseye: resolved (fixed in 5.4.13-1)
forky: resolved (fixed in 5.4.13-1)
sid: resolved (fixed in 5.4.13-1)
trixie: resolved (fixed in 5.4.13-1)
GHSA
GHSA-rmm3-6hwr-c8q9: In the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2019-20636 [HIGH] CWE-787 GHSA-rmm3-6hwr-c8q9: In the Linux kernel before 5
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
OSV
CVE-2019-20636: In input_default_setkeycode of input
osv·2020-07-01
CVE-2019-20636 CVE-2019-20636: In input_default_setkeycode of input
In input_default_setkeycode of input.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2019-20636: In the Linux kernel before 5
osv·2020-04-08·CVSS 6.7
CVE-2019-20636 [MEDIUM] CVE-2019-20636: In the Linux kernel before 5
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20636 kernel: out-of-bounds write via crafted keycode table
bugzilla·2020-04-15·CVSS 6.7
CVE-2019-20636 [MEDIUM] CVE-2019-20636 kernel: out-of-bounds write via crafted keycode table
CVE-2019-20636 kernel: out-of-bounds write via crafted keycode table
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
Upstream commit:
https://github.com/torvalds/linux/commit/cb222aed03d798fc074be55e59d9a112338ee784
Discussion:
Mitigation:
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
---
Statement:
This issue was rated as having Moderate impact because of the need of physical access or administrator privileges to trigger it.
---
This issue has been addressed in the followin
arXiv
Vulnerability Analysis of the Android Kernel
arxiv_fulltext·2021-12-20
Vulnerability Analysis of the Android Kernel
## Abstract
We describe a workflow used to analyze the source code of the Android OS kernel and rate for a particular kind of bugginess that exposes a program to hacking. The workflow represents a novel approach for components' vulnerability rating.
The approach is inspired by recent work on embedding source code functions.
The workflow combines deep learning with heuristics and machine learning. Deep learning is used to embed function/method labels into a Euclidean space. Because the corpus of Android kernel source code is rather limited (containing approximately 2 million C/C++ functions & Java methods), a straightforward embedding is untenable. To overcome the challenge of the dearth of data, it's necessary to go through an intermediate step of the Byte-Pair Encoding.
Subsequently, we
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.12https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cb222aed03d798fc074be55e59d9a112338ee784https://github.com/torvalds/linux/commit/cb222aed03d798fc074be55e59d9a112338ee784https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://security.netapp.com/advisory/ntap-20200430-0004/https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.12https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cb222aed03d798fc074be55e59d9a112338ee784https://github.com/torvalds/linux/commit/cb222aed03d798fc074be55e59d9a112338ee784https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://security.netapp.com/advisory/ntap-20200430-0004/
2020-04-08
Published