PT-2019-5817 · Linux+5 · Linux Kernel+5

Publicado

2019-04-23

·

Atualizado

2023-03-03

·

CVE-2019-11884

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0.15
Description The issue is related to the do hidp sock ioctl function in the Linux kernel, which does not properly handle input data. This can allow a local user to obtain potentially sensitive information from kernel stack memory by using a HIDPCONNADD command. The problem arises because a name field may not end with a '0' character, leading to potential information disclosure.
Recommendations For Linux kernel versions prior to 5.0.15, update to version 5.0.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the do hidp sock ioctl function until a patch is available. Avoid using the HIDPCONNADD command in the affected API endpoint until the issue is resolved.

Correção

Buffer Overflow

NULL Pointer Dereference

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1793
ALT-PU-2019-1830
ALT-PU-2019-1896
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-02777
BDU:2021-03082
CESA-2019_3309
CESA-2019_3517
CESA-2020_1016
CVE-2019-11884
DLA-1823-1
DLA-1824-1
DSA-4465-1
OPENSUSE-SU-2019:1404-1
OPENSUSE-SU-2019:1479-1
OPENSUSE-SU-2019_1404-1
OPENSUSE-SU-2019_1407-1
OPENSUSE-SU-2019_1479-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:0740
RHSA-2020:1016
RHSA-2020:1070
RHSA-2020_1016
RHSA-2020_1070
SUSE-SU-2019:14089-1
SUSE-SU-2019:1527-1
SUSE-SU-2019:1529-1
SUSE-SU-2019:1530-1
SUSE-SU-2019:1532-1
SUSE-SU-2019:1533-1
SUSE-SU-2019:1534-1
SUSE-SU-2019:1535-1
SUSE-SU-2019:1536-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:1692-1
SUSE-SU-2019:2430-1
SUSE-SU-2019_14089-1
USN-4068-1
USN-4068-2
USN-4069-1
USN-4069-2
USN-4076-1
USN-4118-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu