Bug 1824059 (CVE-2019-20636) - CVE-2019-20636 kernel: out-of-bounds write via crafted keycode table
Summary: CVE-2019-20636 kernel: out-of-bounds write via crafted keycode table
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-20636
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1828222 1828223 1828224 1828225 1828226 1888661 1894486 1894487 1894489 1894490
Blocks: 1824060
TreeView+ depends on / blocked
 
Reported: 2020-04-15 08:10 UTC by Marian Rehak
Modified: 2024-03-25 15:49 UTC (History)
54 users (show)

Fixed In Version: kernel 5.4.12
Doc Type: If docs needed, set a value
Doc Text:
An out-of-bounds write flaw was found in the Linux kernel. A crafted keycode table could be used by drivers/input/input.c to perform the out-of-bounds write. A local user with root access can insert garbage to this keycode table that can lead to out-of-bounds memory access. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Clone Of:
Environment:
Last Closed: 2020-07-07 19:28:10 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2020:4416 0 None None None 2020-10-29 15:10:31 UTC
Red Hat Product Errata RHBA-2020:4417 0 None None None 2020-10-29 15:09:00 UTC
Red Hat Product Errata RHBA-2020:4418 0 None None None 2020-10-29 15:14:24 UTC
Red Hat Product Errata RHBA-2020:4419 0 None None None 2020-10-29 15:12:53 UTC
Red Hat Product Errata RHBA-2020:4420 0 None None None 2020-10-29 15:51:44 UTC
Red Hat Product Errata RHSA-2020:2854 0 None None None 2020-07-07 13:19:00 UTC
Red Hat Product Errata RHSA-2020:4060 0 None None None 2020-09-29 20:54:04 UTC
Red Hat Product Errata RHSA-2020:4062 0 None None None 2020-09-29 18:59:45 UTC
Red Hat Product Errata RHSA-2020:4431 0 None None None 2020-11-04 00:50:53 UTC
Red Hat Product Errata RHSA-2020:4609 0 None None None 2020-11-04 02:23:09 UTC
Red Hat Product Errata RHSA-2020:5430 0 None None None 2020-12-15 08:55:25 UTC
Red Hat Product Errata RHSA-2020:5656 0 None None None 2020-12-22 09:32:43 UTC
Red Hat Product Errata RHSA-2021:0019 0 None None None 2021-01-05 10:20:36 UTC

Description Marian Rehak 2020-04-15 08:10:27 UTC
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.

Upstream commit:

https://github.com/torvalds/linux/commit/cb222aed03d798fc074be55e59d9a112338ee784

Comment 11 Alex 2020-04-27 10:29:19 UTC
Mitigation:

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Comment 13 Alex 2020-04-27 11:01:54 UTC
Statement:

This issue was rated as having Moderate impact because of the need of physical access or administrator privileges to trigger it.

Comment 22 errata-xmlrpc 2020-07-07 13:18:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:2854 https://access.redhat.com/errata/RHSA-2020:2854

Comment 23 Product Security DevOps Team 2020-07-07 19:28:10 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-20636

Comment 28 errata-xmlrpc 2020-09-29 18:59:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:4062 https://access.redhat.com/errata/RHSA-2020:4062

Comment 29 errata-xmlrpc 2020-09-29 20:53:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:4060 https://access.redhat.com/errata/RHSA-2020:4060

Comment 46 errata-xmlrpc 2020-11-04 00:50:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:4431 https://access.redhat.com/errata/RHSA-2020:4431

Comment 47 errata-xmlrpc 2020-11-04 02:23:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:4609 https://access.redhat.com/errata/RHSA-2020:4609

Comment 50 errata-xmlrpc 2020-12-15 08:55:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.4 Advanced Update Support
  Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.4 Telco Extended Update Support

Via RHSA-2020:5430 https://access.redhat.com/errata/RHSA-2020:5430

Comment 51 errata-xmlrpc 2020-12-22 09:32:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.6 Extended Update Support

Via RHSA-2020:5656 https://access.redhat.com/errata/RHSA-2020:5656

Comment 53 errata-xmlrpc 2021-01-05 10:20:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Extended Update Support

Via RHSA-2021:0019 https://access.redhat.com/errata/RHSA-2021:0019


Note You need to log in before you can comment on or make changes to this bug.