PT-2019-5817 · Linux+5 · Linux Kernel+5

Published

2019-04-23

·

Updated

2023-03-03

·

CVE-2019-11884

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0.15
Description The issue is related to the do hidp sock ioctl function in the Linux kernel, which does not properly handle input data. This can allow a local user to obtain potentially sensitive information from kernel stack memory by using a HIDPCONNADD command. The problem arises because a name field may not end with a '0' character, leading to potential information disclosure.
Recommendations For Linux kernel versions prior to 5.0.15, update to version 5.0.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the do hidp sock ioctl function until a patch is available. Avoid using the HIDPCONNADD command in the affected API endpoint until the issue is resolved.

Fix

Buffer Overflow

NULL Pointer Dereference

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1793
ALT-PU-2019-1830
ALT-PU-2019-1896
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-02777
BDU:2021-03082
CESA-2019_3309
CESA-2019_3517
CESA-2020_1016
CVE-2019-11884
DLA-1823-1
DLA-1824-1
DSA-4465-1
OPENSUSE-SU-2019:1404-1
OPENSUSE-SU-2019:1479-1
OPENSUSE-SU-2019_1404-1
OPENSUSE-SU-2019_1407-1
OPENSUSE-SU-2019_1479-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:0740
RHSA-2020:1016
RHSA-2020:1070
RHSA-2020_1016
RHSA-2020_1070
SUSE-SU-2019:14089-1
SUSE-SU-2019:1527-1
SUSE-SU-2019:1529-1
SUSE-SU-2019:1530-1
SUSE-SU-2019:1532-1
SUSE-SU-2019:1533-1
SUSE-SU-2019:1534-1
SUSE-SU-2019:1535-1
SUSE-SU-2019:1536-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:1692-1
SUSE-SU-2019:2430-1
SUSE-SU-2019_14089-1
USN-4068-1
USN-4068-2
USN-4069-1
USN-4069-2
USN-4076-1
USN-4118-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu