CVE-2020-12464 is a use-after-free vulnerability in the usb_sg_cancel function within the Linux kernel (before version 5.6.8), specifically affecting drivers/usb/core/message.c, and also impacting NetApp products. This vulnerability carries a CVSS score of 6.7 (Medium), indicating that a highly privileged local attacker could achieve high confidentiality, integrity, and availability impacts with low attack complexity. While the vulnerability is not listed in the KEV catalog and has no known public exploits or community discussion, its potential for significant system compromise warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.16.85CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.17, < 4.4.221CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.221CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.178CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.119CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-12464
Sep 8, 2020usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
Apr 14, 2020kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
Mar 23, 2020