CVE-2020-0465
published 2020-12-14CVE-2020-0465: In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege…
PriorityP427medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.8.7-1 (bookworm) | linux 5.8.7-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | >= 0 < 5.8.7-1 | 5.8.7-1 |
| linux | linux_kernel | >= 0 < 5.8.7-1 | 5.8.7-1 |
| linux | linux_kernel | >= 0 < 5.8.7-1 | 5.8.7-1 |
| linux | linux_kernel | >= 0 < 5.8.7-1 | 5.8.7-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-0465: In hid_output_report of hid-core
osv·2022-12-01
CVE-2020-0465 CVE-2020-0465: In hid_output_report of hid-core
In hid_output_report of hid-core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
GHSA
GHSA-xp58-v8qq-x8jr: In various methods of hid-multitouch
ghsa_unreviewed·2022-05-24
CVE-2020-0465 [HIGH] CWE-787 GHSA-xp58-v8qq-x8jr: In various methods of hid-multitouch
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
OSV
linux-oem-5.6 vulnerabilities
osv·2021-04-13·CVSS 7.8
CVE-2021-29154 [HIGH] linux-oem-5.6 vulnerabilities
linux-oem-5.6 vulnerabilities
Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux
kernel did not properly validate computation of branch displacements in
some situations. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2021-29154)
It was discovered that a race condition existed in the binder IPC
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-0423)
It was discovered that the HID multitouch implementation within the Linux
kernel did not properly validate input events in some situations. A
physically proximate attacker could use this to cause a denial
OSV
CVE-2020-0465: In various methods of hid-multitouch
osv·2020-12-14·CVSS 6.8
CVE-2020-0465 [MEDIUM] CVE-2020-0465: In various methods of hid-multitouch
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
OSV
CVE-2020-0465: In various methods of hid-multitouch
osv·2020-12-01
CVE-2020-0465 CVE-2020-0465: In various methods of hid-multitouch
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2021-04-13·CVSS 7.8
CVE-2020-14351 [HIGH] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux
kernel did not properly validate computation of branch displacements in
some situations. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2021-29154)
It was discovered that a race condition existed in the binder IPC
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-0423)
It was discovered that the HID multitouch implementation within the Linux
kernel did not properly validate input events in som
Red Hat
kernel: out of bounds write in hid-multitouch.c may lead to escalation of privilege
vendor_redhat·2021-01-18·CVSS 6.8
CVE-2020-0465 [MEDIUM] CWE-20 kernel: out of bounds write in hid-multitouch.c may lead to escalation of privilege
kernel: out of bounds write in hid-multitouch.c may lead to escalation of privilege
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
A flaw was found in the Linux kernel’s multi-touch input system. An out-of-bounds write triggered by a use-after-free issue could lead to memory corruption or possible privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Mitigation: As the multitouch module will be auto-loaded when requi
Android
CVE-2020-0465: Kernel
vendor_android·2020-12-01·CVSS 6.8
CVE-2020-0465 [MEDIUM] CVE-2020-0465: Kernel
Android Security Bulletin 2020-12-01
CVE: CVE-2020-0465
Severity: HIGH
Type: EoP
Component: Kernel
References: A-162844689
Upstream kernel
[2]
Debian
CVE-2020-0465: linux - In various methods of hid-multitouch.c, there is a possible out of bounds write ...
vendor_debian·2020·CVSS 6.8
CVE-2020-0465 [MEDIUM] CVE-2020-0465: linux - In various methods of hid-multitouch.c, there is a possible out of bounds write ...
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.8.7-1)
bullseye: resolved (fixed in 5.8.7-1)
forky: resolved (fixed in 5.8.7-1)
sid: resolved (fixed in 5.8.7-1)
trixie: resolved (fixed in 5.8.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-14
Published