PT-2019-4466 · Linux+2 · Linux Kernel+2
Or Cohen
·
Published
2019-11-24
·
Updated
2024-06-15
·
CVE-2019-19252
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 5.3.13
Description
The issue is related to the
vcs write function in the Linux kernel, specifically in the drivers/tty/vt/vc screen.c file. It involves a buffer overflow in memory, which could allow an attacker to elevate their privileges. The problem is that vcs write does not prevent write access to vcsu devices.Recommendations
For Linux kernel versions through 5.3.13, consider restricting access to the
vcsu devices as a temporary workaround until a patch is available. Additionally, monitor for any updates from the Linux kernel community that may address this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Ubuntu