kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
Published Apr 29, 2020
6.7
MEDIUMCVSS 3.1
EPSS 0.80%
Description
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
Affected products
No data.
Configuration 1
- < 3.16.85
- ≥ 3.17 · < 4.4.221
- ≥ 4.5 · < 4.9.221
- ≥ 4.10 · < 4.14.178
- ≥ 4.15 · < 4.19.119
- ≥ 4.20 · < 5.4.36
- ≥ 5.5 · < 5.6.8
Configuration 2
- n/a
- n/a
- h300s
- h410c
- h410s
- h500s
- h610c
- h610s
- h615c
- h700s
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-305.el8
Fixed · RHSA-2021:1578
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-305.rt7.72.el8
Fixed · RHSA-2021:1739
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-305.el8 | Fixed | RHSA-2021:1578 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-305.rt7.72.el8 | Fixed | RHSA-2021:1739 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (22)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-12464 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1831726 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.8 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4773 Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=056ad39ee9253873522f6469c3364964a322912b x_refsource_MISCPatchVendor Advisory
- https://github.com/torvalds/linux/commit/056ad39ee9253873522f6469c3364964a322912b x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lkml.org/lkml/2020/3/23/52 x_refsource_MISCExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-12464
- https://patchwork.kernel.org/patch/11463781/ x_refsource_MISCPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20200608-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4387-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4388-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4389-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4390-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4391-1/ vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2020-12464
- https://www.debian.org/security/2020/dsa-4698 vendor-advisoryx_refsource_DEBIANThird Party AdvisoryVDB Entry
- https://www.debian.org/security/2020/dsa-4699 vendor-advisoryx_refsource_DEBIANThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.