PT-2019-4508 · Linux+5 · Linux Kernel+5

Publicado

2019-10-03

·

Atualizado

2021-05-28

·

CVE-2019-19532

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.3.9
Description The issue is related to out-of-bounds write bugs in the Linux kernel HID drivers, which can be caused by a malicious USB device. This affects various drivers, including drivers/hid/hid-axff.c, drivers/hid/hid-dr.c, drivers/hid/hid-emsff.c, drivers/hid/hid-gaff.c, drivers/hid/hid-holtekff.c, drivers/hid/hid-lg2ff.c, drivers/hid/hid-lg3ff.c, drivers/hid/hid-lg4ff.c, drivers/hid/hid-lgff.c, drivers/hid/hid-logitech-hidpp.c, drivers/hid/hid-microsoft.c, drivers/hid/hid-sony.c, drivers/hid/hid-tmff.c, and drivers/hid/hid-zpff.c. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information using a malicious USB device.
Recommendations For Linux kernel versions prior to 5.3.9, update to version 5.3.9 or later to resolve the issue. As a temporary workaround, consider disabling the use of USB devices from untrusted sources until a patch is applied. Restrict access to the affected HID drivers to minimize the risk of exploitation.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3113
ALT-PU-2019-3136
ALT-PU-2019-3184
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-00369
CESA-2020_1567
CESA-2020_1769
CESA-2021_0856
CVE-2019-19532
DLA-2068-1
DLA-2114-1
OPENSUSE-SU-2020:0336-1
OPENSUSE-SU-2020_0336-1
RHSA-2020:1567
RHSA-2020:1769
RHSA-2020_1567
RHSA-2020_1769
RHSA-2021:0856
RHSA-2021:0857
RHSA-2021:1531
RHSA-2021:2164
RHSA-2021:2355
RHSA-2021_0856
RHSA-2021_0857
SUSE-SU-2019:3316-1
SUSE-SU-2019:3379-1
SUSE-SU-2019:3381-1
SUSE-SU-2019:3389-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:0511-1
SUSE-SU-2020:0560-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020:14354-1
USN-4226-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu