Tracker / CVE-2020-13143
CVE-2020-13143
Medium 6.5
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| linux | linux_kernel · 3.16 → 5.6.13 |
| netapp | a700s_firmware |
| netapp | active_iq_unified_manager |
| netapp | bootstrap_os |
| netapp | cloud_backup |
| netapp | element_software |
| netapp | h300e_firmware |
| netapp | h300s_firmware |
| netapp | h410c_firmware |
| netapp | h410s_firmware |
| netapp | h500e_firmware |
| netapp | h500s_firmware |
| netapp | h610c_firmware |
| netapp | h610s_firmware |
| netapp | h615c_firmware |
| netapp | h700e_firmware |
| netapp | h700s_firmware |
| netapp | hci_management_node |
| netapp | solidfire |
| netapp | solidfire_baseboard_management_controller_firmware |
| netapp | steelstore_cloud_integrated_storage |
| opensuse | leap |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.