PT-2020-2219 · Linux+6 · Linux Kernel+6

Johan Hovold

·

Published

2020-03-12

·

Updated

2021-05-28

·

CVE-2020-11608

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.6.1
Description An issue in the Linux kernel allows NULL pointer dereferences in ov511 mode init regs and ov518 mode init regs functions, located in drivers/media/usb/gspca/ov519.c, when there are zero endpoints. This can potentially lead to a denial of service.
Recommendations For Linux kernel versions prior to 5.6.1, update to version 5.6.1 or later to resolve the issue. As a temporary workaround, consider disabling the ov511 mode init regs and ov518 mode init regs functions until a patch is available.

Fix

Use After Free

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1578
ALT-PU-2020-1671
ALT-PU-2020-1673
ALT-PU-2020-1761
ALT-PU-2020-1917
ALT-PU-2020-2153
ALT-PU-2020-2164
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2020-02134
CESA-2021_1578
CESA-2021_1739
CVE-2020-11608
DLA-2241-1
DLA-2241-2
DLA-2242-1
DSA-4698-1
MGASA-2020-0183
MGASA-2020-0184
OPENSUSE-SU-2020:0801-1
OPENSUSE-SU-2020_0801-1
RHSA-2021:1578
RHSA-2021:1739
RHSA-2021_1578
RHSA-2021_1739
SUSE-SU-2020:1255-1
SUSE-SU-2020:1275-1
SUSE-SU-2020:14354-1
SUSE-SU-2020:1663-1
SUSE-SU-2020_1663-1
USN-4345-1
USN-4364-1
USN-4368-1
USN-4369-1

Affected Products

Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu