← Back to CVE List

CVE-2020-13143

Published: 2020-05-18T18:15Z
Last Modified: 2024-11-21T05:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt