CVE-2019-20636: High severity Google Android vulnerability
An out-of-bounds write flaw was found in the Linux kernel. A crafted keycode table could be used by drivers/input/input.c to perform the out-of-bounds write. A local user with root access can insert garbage to this keycode table that can lead to out-of-bounds memory access. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by inputsetkeycode, aka CID-cb222aed03d7.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-20636?
CVE-2019-20636 is an out-of-bounds write vulnerability in the Linux kernel.
How does CVE-2019-20636 work?
CVE-2019-20636 allows a local user with root access to insert garbage to the keycode table and perform an out-of-bounds write, leading to potential memory access issues.
What is the severity of CVE-2019-20636?
CVE-2019-20636 has a severity score of 6.7, indicating a high severity.
Which versions of the Linux kernel are affected by CVE-2019-20636?
The Linux kernel versions before 5.4.12 are affected by CVE-2019-20636.
How can I fix CVE-2019-20636?
To fix CVE-2019-20636, update your Linux kernel to version 5.4.12 or higher.