NULL pointer dereference in Linux kernel - CVE-2020-11609
Published: May 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the stv06xx subsystem in the "drivers/media/usb/gspca/stv06xx/stv06xx.c" and "drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c" files. A remote authenticated attacker can perform a denial of service (DoS) attack.
Affected software
Anolis OS
Slackware Linux
linux-4.4.227/kernel-modules
linux-4.4.227/kernel-huge
linux-4.4.227/kernel-generic
linux-4.4.227/kernel-headers
kernel-debug-modules
kernel-debug-devel
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-modules-internal
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
bpftool
kernel-debug-core
kernel-debug
kernel-core
kernel
python-perf
How to mitigate CVE-2020-11609
linux-4.4.227/kernel-modules - update to 4.4.227
linux-4.4.227/kernel-huge - update to 4.4.227
linux-4.4.227/kernel-generic - update to 4.4.227
linux-4.4.227/kernel-headers - update to 4.4.227_smp
kernel-debug-modules - update to 4.19.91-26
kernel-debug-devel - update to 4.19.91-26
kernel-debug-modules-extra - update to 4.19.91-26
kernel-devel - update to 4.19.91-26
kernel-headers - update to 4.19.91-26
kernel-modules - update to 4.19.91-26
kernel-modules-extra - update to 4.19.91-26
kernel-modules-internal - update to 4.19.91-26
kernel-tools - update to 4.19.91-26
kernel-tools-libs - update to 4.19.91-26
kernel-tools-libs-devel - update to 4.19.91-26
perf - update to 4.19.91-26
python3-perf - update to 4.19.91-26
bpftool - update to 4.19.91-26
kernel-debug-core - update to 4.19.91-26
kernel-debug - update to 4.19.91-26
kernel-core - update to 4.19.91-26
kernel - update to 4.19.91-26
python-perf - update to 4.19.91-26
External References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.1
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=485b06aadb933190f4bc44e006076bc27a23f205
- https://github.com/torvalds/linux/commit/485b06aadb933190f4bc44e006076bc27a23f205
- https://security.netapp.com/advisory/ntap-20200430-0004/
- https://usn.ubuntu.com/4345-1/
- https://usn.ubuntu.com/4364-1/
- https://usn.ubuntu.com/4368-1/