Vulnerability Description
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | - | |
| Oracle | Communications Cloud Native Core Binding Support Function | 22.1.3 |
| Oracle | Communications Cloud Native Core Network Exposure Function | 22.1.1 |
| Oracle | Communications Cloud Native Core Policy | 22.2.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.htmlThird Party Advisory
- https://source.android.com/security/bulletin/2020-09-01Vendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.htmlThird Party Advisory
- https://source.android.com/security/bulletin/2020-09-01Vendor Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
FAQ
What is CVE-2020-0404?
CVE-2020-0404 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional ex...
How severe is CVE-2020-0404?
CVE-2020-0404 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-0404?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Network Exposure Function, Oracle Communications Cloud Native Core Policy.