CVE-2020-0404
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2020-0404 is a vulnerability discovered in the uvc_scan_chain_forward function of uvc_driver.c that could lead to linked list corruption. This vulnerability affects the Android kernel and Linux kernel systems. The issue was disclosed in the Android Security Bulletin of September 2020 and could allow local escalation of privilege without requiring additional execution privileges or user interaction (Android Bulletin).

Technical details

The vulnerability exists in the uvc_scan_chain_forward function within the uvc_driver.c file, which can lead to linked list corruption due to an unusual root cause. The issue affects the kernel's USB Video Class (UVC) driver implementation (MITRE CVE).

Impact

If exploited, this vulnerability could lead to local escalation of privilege in the kernel. The attacker would not need additional execution privileges to exploit this vulnerability, making it particularly concerning for system security (Red Hat).

Exploitability

The vulnerability can be exploited locally without requiring additional execution privileges. No user interaction is needed for exploitation, making it relatively straightforward for an attacker with local access to exploit (Debian Tracker).

Mitigation and workarounds

The vulnerability has been patched in various Linux distributions. Red Hat has released kernel updates to address this issue in their Enterprise Linux distributions. The fix involves updating the kernel packages to versions that contain the security patch (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68426MEDIUM4.7
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-modules-core
NoYesAug 10, 2026
CVE-2026-68425MEDIUM4.3
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesAug 10, 2026
CVE-2026-68422LOW3.3
  • Linux Kernel logoLinux Kernel
  • linux
NoYesAug 10, 2026
CVE-2026-68428NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.12
NoYesAug 10, 2026
CVE-2026-68421NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.12
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management