Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-20636


In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.


Published

2020-04-08T14:15:12.600

Last Modified

2024-11-21T04:38:56.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 3.16.83 Yes
Operating System linux linux_kernel < 4.4.210 Yes
Operating System linux linux_kernel < 4.9.210 Yes
Operating System linux linux_kernel < 4.14.165 Yes
Operating System linux linux_kernel < 4.19.96 Yes
Operating System linux linux_kernel < 5.4.12 Yes
Application netapp cloud_backup - Yes
Application netapp solidfire - Yes
Application netapp steelstore_cloud_integrated_storage - Yes
Hardware netapp fas_8300 - Yes
Hardware netapp fas_8700 - Yes
Hardware netapp fas_a400 - Yes
Hardware netapp fas_baseboard_management_controller_a220 - Yes
Hardware netapp fas_baseboard_management_controller_a320 - Yes
Hardware netapp fas_baseboard_management_controller_a800 - Yes
Hardware netapp fas_baseboard_management_controller_c190 - Yes
Hardware netapp h300s - Yes
Hardware netapp h410s - Yes
Hardware netapp h500s - Yes
Hardware netapp h610c - Yes
Hardware netapp h610s - Yes
Hardware netapp h615c - Yes
Hardware netapp h700s - Yes

References