In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7. (CVE-2019-20636)
Impact
A local user with root access can insert garbage to this keycode table that can lead to out-of-bounds memory access. This vulnerability may lead to issues with data confidentiality and integrity as well as system availability.