CVE-2020-0404
published 2020-09-17CVE-2020-0404: In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.4.19-1 (bookworm) | linux 5.4.19-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
kernel: avoid cyclic entity chains due to malformed USB descriptors
vendor_redhat·2021-01-16·CVSS 5.5
CVE-2020-0404 [MEDIUM] CWE-284 kernel: avoid cyclic entity chains due to malformed USB descriptors
kernel: avoid cyclic entity chains due to malformed USB descriptors
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
A flaw linked list corruption in the Linux kernel for USB Video Class driver functionality was found in the way user connects web camera to the USB port. A local user could use this flaw to crash the system.
Mitigation: To mitigate this issue, prevent the module uvcvideo from being loaded. Please see https://access.redhat.com/solutions/41278 for information on
Android
CVE-2020-0404: USB driver
vendor_android·2020-09-01·CVSS 5.5
CVE-2020-0404 [MEDIUM] CVE-2020-0404: USB driver
Android Security Bulletin 2020-09-01
CVE: CVE-2020-0404
Severity: HIGH
Type: EoP
Component: USB driver
References: A-111893654
Upstream kernel
Debian
CVE-2020-0404: linux - In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corru...
vendor_debian·2020·CVSS 5.5
CVE-2020-0404 [MEDIUM] CVE-2020-0404: linux - In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corru...
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.4.19-1)
bullseye: resolved (fixed in 5.4.19-1)
forky: resolved (fixed in 5.4.19-1)
sid: resolved (fixed in 5.4.19-1)
trixie: resolved (fixed in 5.4.19-1)
GHSA
GHSA-mrvf-vwcf-3ghc: In uvc_scan_chain_forward of uvc_driver
ghsa_unreviewed·2022-05-24
CVE-2020-0404 [HIGH] CWE-269 GHSA-mrvf-vwcf-3ghc: In uvc_scan_chain_forward of uvc_driver
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
OSV
CVE-2020-0404: In uvc_scan_chain_forward of uvc_driver
osv·2020-09-17·CVSS 5.5
CVE-2020-0404 [MEDIUM] CVE-2020-0404: In uvc_scan_chain_forward of uvc_driver
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
OSV
CVE-2020-0404: In uvc_scan_chain_forward of uvc_driver
osv·2020-09-01
CVE-2020-0404 CVE-2020-0404: In uvc_scan_chain_forward of uvc_driver
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.htmlhttps://source.android.com/security/bulletin/2020-09-01https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.htmlhttps://source.android.com/security/bulletin/2020-09-01https://www.oracle.com/security-alerts/cpujul2022.html
2020-09-17
Published