
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-0404 is a vulnerability discovered in the uvc_scan_chain_forward function of uvc_driver.c that could lead to linked list corruption. This vulnerability affects the Android kernel and Linux kernel systems. The issue was disclosed in the Android Security Bulletin of September 2020 and could allow local escalation of privilege without requiring additional execution privileges or user interaction (Android Bulletin).
The vulnerability exists in the uvc_scan_chain_forward function within the uvc_driver.c file, which can lead to linked list corruption due to an unusual root cause. The issue affects the kernel's USB Video Class (UVC) driver implementation (MITRE CVE).
If exploited, this vulnerability could lead to local escalation of privilege in the kernel. The attacker would not need additional execution privileges to exploit this vulnerability, making it particularly concerning for system security (Red Hat).
The vulnerability can be exploited locally without requiring additional execution privileges. No user interaction is needed for exploitation, making it relatively straightforward for an attacker with local access to exploit (Debian Tracker).
The vulnerability has been patched in various Linux distributions. Red Hat has released kernel updates to address this issue in their Enterprise Linux distributions. The fix involves updating the kernel packages to versions that contain the security patch (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."