imPC@ndo IT

Tracker / CVE-2019-20636

CVE-2019-20636

Medium 6.7

In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.

Affected products and versions

linux linux_kernel · … → 3.16.83
linux linux_kernel · 3.17 → 4.4.210
linux linux_kernel · 4.10 → 4.14.165
linux linux_kernel · 4.15 → 4.19.96
linux linux_kernel · 4.20 → 5.4.12
linux linux_kernel · 4.5 → 4.9.210
netapp cloud_backup
netapp fas_8300
netapp fas_8700
netapp fas_a400
netapp fas_baseboard_management_controller_a220
netapp fas_baseboard_management_controller_a320
netapp fas_baseboard_management_controller_a800
netapp fas_baseboard_management_controller_c190
netapp h300s
netapp h410s
netapp h500s
netapp h610c
netapp h610s
netapp h615c
netapp h700s
netapp solidfire
netapp steelstore_cloud_integrated_storage

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References