CVE-2020-12464
published 2020-04-29CVE-2020-12464: usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka…
medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.6.14-1 (bookworm) | linux 5.6.14-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 3.16.85 | 3.16.85 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 5.6.14-1 | 5.6.14-1 |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
| linux | linux_kernel | >= 0 < 4.15.0-106.107 | 4.15.0-106.107 |
| linux | linux_kernel | >= 0 < 5.4.0-37.41 | 5.4.0-37.41 |
| linux | linux_kernel | >= 3.17 < 4.4.221 | 4.4.221 |
| linux | linux_kernel | >= 4.10 < 4.14.178 | 4.14.178 |
| linux | linux_kernel | >= 4.15 < 4.19.119 | 4.19.119 |
| linux | linux_kernel | >= 4.20 < 5.4.36 | 5.4.36 |
| linux | linux_kernel | >= 4.5 < 4.9.221 | 4.9.221 |
| linux | linux_kernel | >= 5.5 < 5.6.8 | 5.6.8 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-3_on_cbl_mariner_1.0 | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
| netapp | hci_baseboard_management_controller | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM