ZeroHour

CVE-2020-13143

CVSS 3.1
6.5 medium
EPSS
5%p91
Published
()
Modified
Description

gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.

Vendors
linuxopensusedebiancanonicalnetapp
Products
linux kernel, leap, debian linux, ubuntu linux, active iq unified manager, cloud backup, element software, hci management node, solidfire, steelstore cloud integrated storage, solidfire baseboard management controller firmware, bootstrap os
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.