Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11668

Опубликовано: 03 янв. 2020
Источник: redhat
CVSS3: 7.1

Описание

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

A NULL pointer dereference flaw was found in the Xirlink camera USB driver 'xirlink-cit' in the Linux kernel. The driver mishandles invalid descriptors leading to a denial-of-service (DoS). This could allow a local attacker with user privilege to crash the system or leak kernel internal information.

Меры по смягчению последствий

Mitigation for this issue is to skip loading the affected module 'xirlink-cit' onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time.

How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernel-altWill not fix
Red Hat Enterprise MRG 2kernel-rtWill not fix
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2021:272621.07.2021
Red Hat Enterprise Linux 7kernelFixedRHSA-2021:272521.07.2021
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2020:460904.11.2020
Red Hat Enterprise Linux 8kernelFixedRHSA-2020:443104.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1824792kernel: mishandles invalid descriptors in drivers/media/usb/gspca/xirlink_cit.c

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 5 лет назад

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

CVSS3: 7.1
nvd
около 5 лет назад

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

CVSS3: 7.1
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.1
debian
около 5 лет назад

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit. ...

suse-cvrf
больше 4 лет назад

Security update for the Linux Kernel (Live Patch 21 for SLE 15)

7.1 High

CVSS3