CVE-2020-0404: Medium severity Google Android vulnerability
A flaw linked list corruption in the Linux kernel for USB Video Class driver functionality was found in the way user connects web camera to the USB port. A local user could use this flaw to crash the system.
Other sources
A vulnerability was found in Kernel, where an avoid cyclic entity chains due to malformed USB descriptors Way back in 2017, fuzzing the 4.14-rc2 USB stack with syzkaller kicked up the UVC chain scanning code.
References: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=68035c80e129c4cfec659aac4180354530b26527
— Red Hat
In uvcscanchainforward of uvcdriver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-0404?
CVE-2020-0404 is a high severity vulnerability in the Linux kernel for USB Video Class driver functionality.
How does CVE-2020-0404 impact affected software?
CVE-2020-0404 can lead to local escalation of privilege in the kernel with no additional execution privileges needed.
Is user interaction required for exploitation of CVE-2020-0404?
No, user interaction is not needed for exploitation of CVE-2020-0404.
How can I fix CVE-2020-0404?
To fix CVE-2020-0404, update the affected software to versions 4.18.0-372.9.1.rt7.166.el8 for kernel-rt or 4.18.0-372.9.1.el8 for kernel.
Where can I find more information about CVE-2020-0404?
You can find more information about CVE-2020-0404 at the following references: - [Commit on Git Kernel](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=68035c80e129c4cfec659aac4180354530b26527) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1919792) - [Red Hat Access Solution](https://access.redhat.com/solutions/41278)