CVE-2020-7456: Buffer Overflow
In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processing of that HID item allowing an attacker with physical access to a USB port to be able to use a specially crafted USB device to gain kernel or user-space code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7456?
The severity of CVE-2020-7456 is high.
What software is affected by CVE-2020-7456?
FreeBSD 11.3, 11.4, and 12.1 as well as NetApp Clustered Data ONTAP.
How can an attacker exploit CVE-2020-7456?
An attacker can exploit CVE-2020-7456 by using an invalid memory location for HID items.
Is there a fix available for CVE-2020-7456?
Yes, fixes have been released for FreeBSD and NetApp Clustered Data ONTAP. Please refer to the respective advisories for more information.
Where can I find more information about CVE-2020-7456?
Additional information about CVE-2020-7456 can be found in the FreeBSD and NetApp advisories.