CVE-2020-12464
published 2020-04-29CVE-2020-12464: usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.80%
52.9th percentile
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.6.14-1 (bookworm) | linux 5.6.14-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.16.85 | 3.16.85 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
| linux | linux_kernel | >= 0 < 4.15.0-106.107 | 4.15.0-106.107 |
| linux | linux_kernel | >= 0 < 5.4.0-37.41 | 5.4.0-37.41 |
| linux | linux_kernel | >= 3.17 < 4.4.221 | 4.4.221 |
| linux | linux_kernel | >= 4.10 < 4.14.178 | 4.14.178 |
| linux | linux_kernel | >= 4.15 < 4.19.119 | 4.19.119 |
| linux | linux_kernel | >= 4.20 < 5.4.36 | 5.4.36 |
| linux | linux_kernel | >= 4.5 < 4.9.221 | 4.9.221 |
| linux | linux_kernel | >= 5.5 < 5.6.8 | 5.6.8 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-3_on_cbl_mariner_1.0 | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2020-12464: Linux USB Subsystem
vendor_android·2020-08-01·CVSS 6.7
CVE-2020-12464 [MEDIUM] CVE-2020-12464: Linux USB Subsystem
Android Security Bulletin 2020-08-01
CVE: CVE-2020-12464
Severity: HIGH
Type: EoP
Component: Linux USB Subsystem
References: A-156071259
Upstream kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-11·CVSS 6.5
CVE-2019-19319 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle setxattr operations in some situations. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-19319)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-11·CVSS 4.4
CVE-2020-0067 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-10·CVSS 4.4
CVE-2020-0067 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-10·CVSS 4.4
CVE-2020-0067 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-09·CVSS 4.4
CVE-2020-0067 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in
Microsoft
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
vendor_msrc·2020-04-14·CVSS 6.7
CVE-2020-12464 [MEDIUM] CWE-416 usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mar
Red Hat
kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
vendor_redhat·2020-03-23·CVSS 6.7
CVE-2020-12464 [MEDIUM] CWE-416 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
A use-after-free flaw was found in usb_sg_cancel in drivers/usb/core/message.c in the USB core subsystem. This flaw allows a local attacker with a special user or root privileges to crash the system due to a race problem in the scatter-gather cancellation and transfer completion in usb_sg_wait. This vulnerability can also lead to a leak of internal kernel information.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deploym
Debian
CVE-2020-12464: linux - usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has...
vendor_debian·2020·CVSS 6.7
CVE-2020-12464 [MEDIUM] CVE-2020-12464: linux - usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has...
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
Scope: local
bookworm: resolved (fixed in 5.6.14-1)
bullseye: resolved (fixed in 5.6.14-1)
forky: resolved (fixed in 5.6.14-1)
sid: resolved (fixed in 5.6.14-1)
trixie: resolved (fixed in 5.6.14-1)
GHSA
GHSA-jx8c-mxmr-fc68: usb_sg_cancel in drivers/usb/core/message
ghsa_unreviewed·2022-05-24
CVE-2020-12464 [HIGH] CWE-416 GHSA-jx8c-mxmr-fc68: usb_sg_cancel in drivers/usb/core/message
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
OSV
CVE-2020-12464: In usb_sg_cancel of message
osv·2020-08-01
CVE-2020-12464 CVE-2020-12464: In usb_sg_cancel of message
In usb_sg_cancel of message.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-06-11·CVSS 4.4
CVE-2020-0067 [MEDIUM] linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr K
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-06-11·CVSS 6.5
CVE-2019-19319 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle setxattr operations in some situations. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-19319)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in the Linux
OSV
linux, linux-aws, linux-aws-5.3, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerabili
osv·2020-06-10·CVSS 4.4
CVE-2020-0067 [MEDIUM] linux, linux-aws, linux-aws-5.3, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerabili
linux, linux-aws, linux-aws-5.3, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerabilities
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oracle, linux-raspi, linux-riscv vulnerabilities
osv·2020-06-10·CVSS 4.4
CVE-2020-0067 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oracle, linux-raspi, linux-riscv vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oracle, linux-raspi, linux-riscv vulnerabilities
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementat
OSV
linux-gke-5.0, linux-oem-osp1 vulnerabilities
osv·2020-06-09·CVSS 4.4
CVE-2020-0067 [MEDIUM] linux-gke-5.0, linux-oem-osp1 vulnerabilities
linux-gke-5.0, linux-oem-osp1 vulnerabilities
It was discovered that the F2FS file system implementation in the Linux
kernel did not properly perform bounds checking on xattrs in some
situations. A local attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2020-0067)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in the Linux kernel. A local attacker could use this to
ca
OSV
CVE-2020-12464: usb_sg_cancel in drivers/usb/core/message
osv·2020-04-29·CVSS 6.7
CVE-2020-12464 [MEDIUM] CVE-2020-12464: usb_sg_cancel in drivers/usb/core/message
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
Suricata
ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway SQL Injection
suricata·2018-08-24
ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway SQL Injection
ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway SQL Injection
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS MicroFocus Secure Messaging Gateway SQL Injection"; flow:established,to_server; http.uri; content:"/enginelist.php"; fast_pattern; http.request_body; content:"appkey="; pcre:"/^[a-z0-9A-Z]+\x252[270]/R"; reference:url,github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/microfocus_secure_messaging_gateway.rb; classtype:attempted-user; sid:2026036; rev:3; metadata:affected_product PHP, attack_target Web_Server, created_at 2018_08_24, cve cve_2018_12464, deployment Datacenter, signature_severity Major, updated_at 2020_08_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
No public exploits indexed.
Bugzilla
CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c [fedora-all]
bugzilla·2020-05-05·CVSS 6.7
CVE-2020-12464 [MEDIUM] CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c [fedora-all]
CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
bugzilla·2020-05-05·CVSS 6.7
CVE-2020-12464 [MEDIUM] CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
A use-after-free flaw was found in usb_sg_cancel in drivers/usb/core/message.c in USB core subsystem. This flaw could allow a local attacker with special user privilege (or root) to crash the system due to a race problem in scatter-gather cancellation and transfer completion in usb_sg_wait. This vulnerability can even lead to a kernel information leak problem .
Here usb_sg_cancel() does not take any reference to the transfer and there is nothing to prevent the URBs from being deallocated while the routine is trying to use them.
Taking a reference by incrementing the transfer's io->count field while the cancellation is in progress and decrementing it afterwards can be way to address this. The tr
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.8https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=056ad39ee9253873522f6469c3364964a322912bhttps://github.com/torvalds/linux/commit/056ad39ee9253873522f6469c3364964a322912bhttps://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://lkml.org/lkml/2020/3/23/52https://patchwork.kernel.org/patch/11463781/https://security.netapp.com/advisory/ntap-20200608-0001/https://usn.ubuntu.com/4387-1/https://usn.ubuntu.com/4388-1/https://usn.ubuntu.com/4389-1/https://usn.ubuntu.com/4390-1/https://usn.ubuntu.com/4391-1/https://www.debian.org/security/2020/dsa-4698https://www.debian.org/security/2020/dsa-4699http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.8https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=056ad39ee9253873522f6469c3364964a322912bhttps://github.com/torvalds/linux/commit/056ad39ee9253873522f6469c3364964a322912bhttps://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://lkml.org/lkml/2020/3/23/52https://patchwork.kernel.org/patch/11463781/https://security.netapp.com/advisory/ntap-20200608-0001/https://usn.ubuntu.com/4387-1/https://usn.ubuntu.com/4388-1/https://usn.ubuntu.com/4389-1/https://usn.ubuntu.com/4390-1/https://usn.ubuntu.com/4391-1/https://www.debian.org/security/2020/dsa-4698https://www.debian.org/security/2020/dsa-4699
2020-04-29
Published