Lucene search

K
redhatcveRedhat.comRH:CVE-2020-12464
HistoryMay 05, 2020 - 2:39 p.m.

CVE-2020-12464

2020-05-0514:39:51
redhat.com
access.redhat.com
31

0.001 Low

EPSS

Percentile

43.3%

A use-after-free flaw was found in usb_sg_cancel in drivers/usb/core/message.c in the USB core subsystem. This flaw allows a local attacker with a special user or root privileges to crash the system due to a race problem in the scatter-gather cancellation and transfer completion in usb_sg_wait. This vulnerability can also lead to a leak of internal kernel information.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.