Vulnerability Description
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 3.16.85 |
| Netapp | Active Iq Unified Manager | - |
| Netapp | Cloud Backup | - |
| Netapp | Hci Baseboard Management Controller | h300s |
| Netapp | Hci Storage Nodes | - |
| Netapp | Solidfire \& Hci Storage Node | - |
| Netapp | Steelstore Cloud Integrated Storage | - |
| Netapp | Aff A700S | - |
| Netapp | Hci Compute Node | - |
| Netapp | Solidfire Baseboard Management Controller | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.8Release NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=056adPatchVendor Advisory
- https://github.com/torvalds/linux/commit/056ad39ee9253873522f6469c3364964a322912PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlThird Party Advisory
- https://lkml.org/lkml/2020/3/23/52ExploitVendor Advisory
- https://patchwork.kernel.org/patch/11463781/PatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20200608-0001/Third Party Advisory
- https://usn.ubuntu.com/4387-1/Third Party Advisory
- https://usn.ubuntu.com/4388-1/Third Party Advisory
- https://usn.ubuntu.com/4389-1/Third Party Advisory
- https://usn.ubuntu.com/4390-1/Third Party Advisory
- https://usn.ubuntu.com/4391-1/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2020-12464?
CVE-2020-12464 is a vulnerability with a CVSS score of 6.7 (MEDIUM). usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
How severe is CVE-2020-12464?
CVE-2020-12464 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12464?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Netapp Active Iq Unified Manager, Netapp Cloud Backup, Netapp Hci Baseboard Management Controller, Netapp Hci Storage Nodes.