gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
2020-05-18T18:15:11.347
2024-11-21T05:00:44.170
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 5.6.13 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Operating System | opensuse | leap | 15.2 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |
Operating System | canonical | ubuntu_linux | 20.04 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | element_software | - | Yes |
Application | netapp | hci_management_node | - | Yes |
Application | netapp | solidfire | - | Yes |
Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
Operating System | netapp | solidfire_baseboard_management_controller_firmware | - | Yes |
Hardware | netapp | solidfire_baseboard_management_controller | - | No |
Operating System | netapp | bootstrap_os | - | Yes |
Hardware | netapp | hci_compute_node | - | No |
Operating System | netapp | a700s_firmware | - | Yes |
Hardware | netapp | a700s | - | No |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h300e_firmware | - | Yes |
Hardware | netapp | h300e | - | No |
Operating System | netapp | h500e_firmware | - | Yes |
Hardware | netapp | h500e | - | No |
Operating System | netapp | h700e_firmware | - | Yes |
Hardware | netapp | h700e | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | netapp | h410c_firmware | - | Yes |
Hardware | netapp | h410c | - | No |
Operating System | netapp | h610c_firmware | - | Yes |
Hardware | netapp | h610c | - | No |
Operating System | netapp | h610s_firmware | - | Yes |
Hardware | netapp | h610s | - | No |
Operating System | netapp | h615c_firmware | - | Yes |
Hardware | netapp | h615c | - | No |