PT-2019-4438 · Linux+3 · Linux Kernel+3

Aleksandr Popov

+1

·

Published

2019-11-03

·

Updated

2025-09-29

·

CVE-2019-18683

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.3.8
Description The issue is related to a race condition in the V4L2 subsystem of the Linux kernel, specifically in the drivers/media/platform/vivid module. This is caused by incorrect mutex locking in functions such as vivid stop generating vid cap(), vivid stop generating vid out(), and sdr cap stop streaming(). The exploitation of this issue can lead to privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. At least one of these race conditions leads to a use-after-free.
Recommendations For Linux kernel versions prior to 5.3.8, consider updating to a version that includes the fix for this issue. As a temporary workaround, restricting access to the /dev/video0 device or disabling the vivid driver may help minimize the risk of exploitation. Additionally, avoiding the use of the affected functions until a patch is available can also be considered as a mitigation measure.

Exploit

Fix

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2019-3113
ALT-PU-2019-3136
ALT-PU-2019-3184
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-00195
CVE-2019-18683
DLA-2114-1
OPENSUSE-SU-2019:2675-1
OPENSUSE-SU-2019_2675-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3289-1
SUSE-SU-2019:3316-1
SUSE-SU-2019:3317-1
SUSE-SU-2019:3371-1
SUSE-SU-2019:3372-1
SUSE-SU-2019:3379-1
SUSE-SU-2019:3381-1
SUSE-SU-2019_3200-1
SUSE-SU-2019_3289-1
SUSE-SU-2019_3316-1
SUSE-SU-2019_3317-1
SUSE-SU-2019_3371-1
SUSE-SU-2019_3372-1
SUSE-SU-2019_3379-1
SUSE-SU-2019_3381-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1255-1
SUSE-SU-2020_0093-1
SUSE-SU-2020_0613-1
SUSE-SU-2020_1255-1
USN-4254-1
USN-4254-2
USN-4258-1
USN-4284-1
USN-4287-1
USN-4287-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu