PT-2019-4438 · Linux+3 · Linux Kernel+3

Aleksandr Popov

+1

·

Publicado

2019-11-03

·

Atualizado

2025-09-29

·

CVE-2019-18683

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.3.8
Description The issue is related to a race condition in the V4L2 subsystem of the Linux kernel, specifically in the drivers/media/platform/vivid module. This is caused by incorrect mutex locking in functions such as vivid stop generating vid cap(), vivid stop generating vid out(), and sdr cap stop streaming(). The exploitation of this issue can lead to privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. At least one of these race conditions leads to a use-after-free.
Recommendations For Linux kernel versions prior to 5.3.8, consider updating to a version that includes the fix for this issue. As a temporary workaround, restricting access to the /dev/video0 device or disabling the vivid driver may help minimize the risk of exploitation. Additionally, avoiding the use of the affected functions until a patch is available can also be considered as a mitigation measure.

Exploit

Correção

Race Condition

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-3113
ALT-PU-2019-3136
ALT-PU-2019-3184
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-00195
CVE-2019-18683
DLA-2114-1
OPENSUSE-SU-2019:2675-1
OPENSUSE-SU-2019_2675-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3289-1
SUSE-SU-2019:3316-1
SUSE-SU-2019:3317-1
SUSE-SU-2019:3371-1
SUSE-SU-2019:3372-1
SUSE-SU-2019:3379-1
SUSE-SU-2019:3381-1
SUSE-SU-2019_3200-1
SUSE-SU-2019_3289-1
SUSE-SU-2019_3316-1
SUSE-SU-2019_3317-1
SUSE-SU-2019_3371-1
SUSE-SU-2019_3372-1
SUSE-SU-2019_3379-1
SUSE-SU-2019_3381-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020_0093-1
SUSE-SU-2020_0613-1
SUSE-SU-2020_1255-1
USN-4254-1
USN-4254-2
USN-4258-1
USN-4284-1
USN-4287-1
USN-4287-2

Produtos afetados

Alt Linux
Linux Kernel
Suse
Ubuntu