CVE-2020-0465: Input Validation
A flaw was found in the Linux kernel’s multi-touch input system. An out-of-bounds write triggered by a use-after-free issue could lead to memory corruption or possible privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in various methods of hid-multitouch.c. By executing a specially-crafted program, an attacker could exploit this vulnerability to escalate privileges.
— IBM
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=35556bed836f8dc07ac55f69c8d17dce3e7f0e25
— Red Hat
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-0465?
CVE-2020-0465 is considered a high severity vulnerability, impacting confidentiality, integrity, and system availability.
How do I fix CVE-2020-0465?
To fix CVE-2020-0465, update to the patched versions of the affected Linux kernel packages as provided by your distribution.
What causes the CVE-2020-0465 vulnerability?
CVE-2020-0465 is caused by a use-after-free issue in the Linux kernel's multi-touch input system leading to potential memory corruption.
Which systems are affected by CVE-2020-0465?
CVE-2020-0465 affects various systems, including specific versions of Red Hat kernel, Google Android, and IBM Security Guardium.
Can CVE-2020-0465 lead to privilege escalation?
Yes, CVE-2020-0465 can potentially lead to privilege escalation due to memory corruption.