KernelCare update was released

8 views
Skip to first unread message

KernelCare

unread,
Apr 27, 2020, 8:27:10 AM4/27/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

pve-6:
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19079: A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c
in the Linux kernel before 5.3 allows attackers to cause a denial of service (memory
consumption), aka CID-a21b7f0cff19.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2020-8835: ''
cvelist: [CVE-2019-19227, CVE-2019-19066, CVE-2019-19058, CVE-2020-8835, CVE-2019-19079,
CVE-2019-18885, CVE-2019-19068]
latest-version: pve-kernel-5.4.27-1-pve_5.4.27-1

KernelCare

unread,
Apr 28, 2020, 11:05:18 AM4/28/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-aws:
CVE-2016-10723: An issue was discovered in the Linux kernel through 4.17.2. Since
the page allocator does not yield CPU resources to the owner of the oom_lock mutex,
a local unprivileged user can trivially lock up the system forever by wasting
CPU resources from the page allocator (e.g., via concurrent page fault events)
when the global OOM killer is invoked.
CVE-2018-12126: In ONAP DCAE through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12127: In ONAP OOM through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12130: In ONAP CLI through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13093: An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel
through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow()
on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image.
This occurs because of a lack of proper validation that cached inodes are free
during allocation.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-13097: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect
user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).
CVE-2018-13098: An issue was discovered in fs/f2fs/inode.c in the Linux kernel through
4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a
modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel
through 4.17.3. A denial of service (out-of-bounds memory access and BUG) can
occur for a modified f2fs filesystem image in which an inline inode contains an
invalid reserved blkaddr.
CVE-2018-13100: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image,
as demonstrated by a divide-by-zero error.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14610: An issue was discovered in the Linux kernel through 4.17.10. There
is out-of-bounds access in write_extent_buffer() when mounting and operating a
crafted btrfs image, because of a lack of verification that each block group has
a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.
CVE-2018-14611: An issue was discovered in the Linux kernel through 4.17.10. There
is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image,
because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
CVE-2018-14612: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in btrfs_root_node() when mounting a crafted
btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups
in fs/btrfs/extent-tree.c, and a lack of empty-tree checks in check_leaf in fs/btrfs/tree-checker.c.
CVE-2018-14613: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in io_ctl_map_page() when mounting and operating
a crafted btrfs image, because of a lack of block group item validation in check_leaf_item
in fs/btrfs/tree-checker.c.
CVE-2018-14614: An issue was discovered in the Linux kernel through 4.17.10. There
is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when
mounting an f2fs image.
CVE-2018-14615: An issue was discovered in the Linux kernel through 4.17.10. There
is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting
an f2fs image, because a length value may be negative.
CVE-2018-14616: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c
when operating on a file in a corrupted f2fs image.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the
cleancache subsystem clears an inode after the final file truncation (removal).
The new file created with the same inode may contain leftover pages from cleancache
and the old file data instead of the new one.
CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+
shares mounted in different network namespaces at the same time can make bc_svc_process()
use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious
container user can cause a host kernel memory corruption and a system panic. Due
to the nature of the flaw, privilege escalation cannot be fully ruled out.
CVE-2018-19985: The function hso_get_config_data in drivers/net/usb/hso.c in the
Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses
it to index a small array, resulting in an object out-of-bounds (OOB) read that
potentially allows arbitrary read in the kernel address space.
CVE-2018-20169: An issue was discovered in the Linux kernel before 4.19.9. The USB
subsystem mishandles size checks during the reading of an extra descriptor, related
to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-20511: An issue was discovered in the Linux kernel before 4.18.11. The
ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain
sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route
dev and next fields via an SIOCFINDIPDDPRT ioctl call.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles
leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop
in update_blocked_averages) or possibly have unspecified other impact by inducing
a high load.
CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c,
there is an __blk_drain_queue() use-after-free because a certain error case is
mishandled.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2018-21008: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free
can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVE-2018-5383: Bluetooth firmware or operating system software drivers in macOS
versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions
before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters
used to generate public keys during a Diffie-Hellman key exchange, which may allow
a remote attacker to obtain the encryption key used by the device.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10126: A flaw was found in the Linux kernel. A heap based buffer overflow
in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c
might lead to memory corruption and possibly other consequences.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-10638: In the Linux kernel before 5.1.7, a device can be tracked by an
attacker using the IP ID values the kernel produces for connection-less protocols
(e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses,
it is possible to obtain hash collisions (of indices to the counter array) and
thereby obtain the hashing key (via enumeration). An attack may be conducted by
hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled
IP addresses.
CVE-2019-11085: Insufficient input validation in Kernel Mode Driver in Intel(R)
i915 Graphics for Linux before version 5.0 may allow an authenticated user to
potentially enable escalation of privilege via local access.
CVE-2019-11091: 'Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable
memory on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-1125: An information disclosure vulnerability exists when certain central
processing units (CPU) speculatively access memory, aka 'Windows Kernel Information
Disclosure Vulnerability'.
CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs
value was subject to an integer overflow in the Linux kernel when handling TCP
Selective Acknowledgments (SACKs).
CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation
in tcp_fragment in the Linux kernel could be fragmented when handling certain
TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this
to cause a denial of service.
CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is
hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues
significantly more than if a larger MSS were enforced. A remote attacker could
use this to cause a denial of service.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-11599: The coredump implementation in the Linux kernel before 5.0.10 does
not use locking or other mechanisms to prevent vma layout or vma flags changes
while it runs, which allows local users to obtain sensitive information, cause
a denial of service, or possibly have unspecified other impact by triggering a
race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c,
mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL
pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds()
in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service,
related to a use-after-free.
CVE-2019-11815: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero
out the unused memory region in the extent tree block, which might allow local
users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in
the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive
information from kernel stack memory via a HIDPCONNADD command, because a name
field may not end with a '\0' character.
CVE-2019-12818: An issue was discovered in the Linux kernel before 4.20.15. The
nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the
caller does not check for this, it will trigger a NULL pointer dereference. This
will cause denial of service. This affects nfc_llcp_build_gb in net/nfc/llcp_core.c.
CVE-2019-12819: An issue was discovered in the Linux kernel before 5.0. The function
__mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will
trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
CVE-2019-12984: A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target()
in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious
user-mode program that omits certain NFC attributes, leading to denial of service.
CVE-2019-13233: 'In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there
is a use-after-free for access to an LDT entry because of a race condition between
modify_ldt() and a #BR exception for an MPX bounds violation.'
CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c
mishandles the recording of the credentials of a process that wants to create
a ptrace relationship, which allows local users to obtain root access by leveraging
certain scenarios with a parent-child process relationship, where a parent drops
privileges and calls execve (potentially allowing control by an attacker). One
contributing factor is an object lifetime issue (which can also cause a panic).
Another contributing factor is incorrect marking of a ptrace relationship as privileged,
which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14283: 'In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c
does not validate the sect and head fields, as demonstrated by an integer overflow
and out-of-bounds read. It can be triggered by an unprivileged local user when
a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.'
CVE-2019-14284: 'In the Linux kernel before 5.2.3, drivers/block/floppy.c allows
a denial of service by setup_format_params division-by-zero. Two consecutive ioctls
can trigger the bug: the first one should set the drive geometry with .sect and
.rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation
should be called. It can be triggered by an unprivileged local user even when
a floppy disk has not been inserted.'
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14763: In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c
may potentially cause a deadlock with f_hid.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow
was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could be supplied
by a host user-space process. An unprivileged host user or process with access
to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in
a denial of service or potentially escalating privileges on the system.
CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x,
in the way Linux kernel's vhost functionality that translates virtqueue buffers
to IOVs, logged the buffer descriptors during migration. A privileged guest user
able to pass descriptors with invalid length to the host when migration is underway,
could use this flaw to increase their privileges on the host.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15214: An issue was discovered in the Linux kernel before 5.0.10. There
is a use-after-free in the sound subsystem because card disconnection causes certain
data structures to be deleted too early. This is related to sound/core/init.c
and sound/core/info.c.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15666: An issue was discovered in the Linux kernel before 5.0.19. There
is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial
of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory
validation.
CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c
when SAS expander discovery fails. This will cause a BUG and denial of service.
CVE-2019-15916: An issue was discovered in the Linux kernel before 5.0.1. There
is a memory leak in register_queue_kobjects() in net/core/net-sysfs.c, which will
cause denial of service.
CVE-2019-15918: An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate
in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely
updated after a change from smb30 to smb21.
CVE-2019-15921: An issue was discovered in the Linux kernel before 5.0.6. There
is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c.
CVE-2019-15924: An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module
in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference
because there is no -ENOMEM upon an alloc_workqueue failure.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16413: An issue was discovered in the Linux kernel before 5.0.4. The 9p
filesystem did not protect i_size_write() properly, which causes an i_size_read()
infinite loop and denial of service on SMP systems.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service, aka CID-07f12b26e21a.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service, aka CID-6caabe7f197d.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c
in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single
(a DMA function) from a stack variable. This could allow an attacker to trigger
a Denial of Service, exploitable if this driver is used on an architecture for
which this stack/DMA interaction has security relevance.
CVE-2019-17133: In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in
net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19046: A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
CVE-2019-19060: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-ab612b1daf41.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-19065: A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19075: A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c
in the Linux kernel before 5.3.8 allows attackers to cause a denial of service
(memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption). This affects the dce120_create_resource_pool() function
in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
CVE-2019-19083: Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3
has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry
for the Pivotal Platform
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2024: In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use
after free issue. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel.'
CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the
Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical
operations that can be also applied to the can_dlc field. The privileged user
"root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes
the data length code a higher value than the available CAN frame data size. In
combination with a configured checksum calculation where the result is stored
relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb
(e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can
cause a system crash. Because of a missing check, the CAN drivers may write arbitrary
content beyond the data registers in the CAN controller's I/O memory when processing
can-gw manipulated outgoing frames.
CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read()
in drivers/hid/hid-debug.c file which may enter an infinite loop with certain
parameters passed from a userspace. A local privileged user ("root") can cause
a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate
privileges was found in the mwifiex kernel module while connecting to a malicious
wireless network.
CVE-2019-3874: The SCTP socket buffer used by a userspace application is not accounted
by the cgroups subsystem. An attacker can use this flaw to cause a denial of service
attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation
that permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is administratively
granted ownership of the device, it may cause a system memory exhaustion and thus
a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in
Linux Kernel up to and including v5.1-rc6, while handling incoming packets in
handle_rx(). It could occur if one end sends packets faster than the other end
can process them. A guest user, maybe remote one, could use this flaw to stall
the vhost_net kernel thread, resulting in a DoS scenario.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9500: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality
is configured, a malicious event frame can be constructed to trigger an heap buffer
overflow in the brcmf_wowl_nd_results function.
CVE-2019-9503: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f
is vulnerable to a frame validation bypass. If the brcmfmac driver receives a
firmware event frame from a remote source, the is_wlc_event_frame function will
cause this frame to be discarded and unprocessed. If the driver receives the firmware
event frame from the host, the appropriate handler is called. This frame validation
can be bypassed if the bus used is USB (for instance by a wifi dongle). This can
allow firmware event frames from a remote source to be processed. In the worst
case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated
attacker may be able to execute arbitrary code on a vulnerable system. More typically,
this vulnerability will result in denial-of-service conditions.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled
instruction emulation for an L2 guest when nested virtualisation is enabled. Under
some circumstances, an L2 guest may trick the L0 guest into accessing sensitive
L1 resources that should be inaccessible to the L2 guest.
CVE-2020-7053: In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm
through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the
i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
CVE-2020-8428: fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky
use-after-free, which allows local users to cause a denial of service (OOPS) or
possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
One attack vector may be an open system call for a UNIX domain socket, if the
socket is being moved to a new parent directory and its old parent directory is
being removed.
cvelist: [CVE-2019-3701, CVE-2019-17056, CVE-2019-5108, CVE-2018-13093, CVE-2019-0154,
CVE-2018-16862, CVE-2019-19332, CVE-2019-15218, CVE-2019-15215, CVE-2019-19062,
CVE-2019-15220, CVE-2018-14612, CVE-2018-12207, CVE-2019-18786, CVE-2019-0155,
CVE-2019-17133, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091,
CVE-2019-15221, CVE-2019-15211, CVE-2019-11810, CVE-2019-16746, CVE-2019-19082,
CVE-2019-14816, CVE-2019-15090, CVE-2019-11884, CVE-2019-1125, CVE-2019-3900,
CVE-2018-19985, CVE-2019-19065, CVE-2019-14815, CVE-2018-13100, CVE-2019-16232,
CVE-2019-17055, CVE-2019-15214, CVE-2019-14615, CVE-2019-18885, CVE-2019-16413,
CVE-2019-15916, CVE-2018-21008, CVE-2018-5383, CVE-2020-2732, CVE-2019-15924,
CVE-2019-19083, CVE-2019-18683, CVE-2019-19767, CVE-2019-19524, CVE-2019-16995,
CVE-2019-15921, CVE-2019-11085, CVE-2019-19060, CVE-2018-14610, CVE-2019-14897,
CVE-2019-14821, CVE-2019-9503, CVE-2019-17075, CVE-2019-11599, CVE-2020-7053,
CVE-2019-9506, CVE-2018-20784, CVE-2018-20169, CVE-2019-17052, CVE-2019-15918,
CVE-2019-15291, CVE-2019-15217, CVE-2018-14616, CVE-2019-11833, CVE-2018-13097,
CVE-2018-13099, CVE-2019-15505, CVE-2019-15666, CVE-2019-15098, CVE-2019-11478,
CVE-2019-10638, CVE-2019-2024, CVE-2019-11815, CVE-2019-19063, CVE-2018-20511,
CVE-2019-10126, CVE-2019-12984, CVE-2019-3874, CVE-2019-14284, CVE-2018-13053,
CVE-2019-19078, CVE-2019-19965, CVE-2019-10207, CVE-2019-19071, CVE-2019-14835,
CVE-2019-16233, CVE-2019-16231, CVE-2019-3819, CVE-2019-11486, CVE-2019-19227,
CVE-2019-17054, CVE-2019-12819, CVE-2019-19052, CVE-2019-13233, CVE-2019-20096,
CVE-2019-11479, CVE-2019-13272, CVE-2019-19056, CVE-2019-18809, CVE-2019-19046,
CVE-2019-3882, CVE-2019-14901, CVE-2019-5489, CVE-2018-16884, CVE-2019-19068,
CVE-2020-8428, CVE-2019-19057, CVE-2019-19058, CVE-2019-9500, CVE-2019-16994,
CVE-2019-19051, CVE-2019-15099, CVE-2018-14615, CVE-2019-3846, CVE-2019-15212,
CVE-2019-19529, CVE-2018-13096, CVE-2018-14617, CVE-2019-16229, CVE-2018-20976,
CVE-2016-10723, CVE-2019-15538, CVE-2018-13098, CVE-2019-13631, CVE-2018-14611,
CVE-2019-12818, CVE-2019-11487, CVE-2019-14283, CVE-2019-19075, CVE-2019-17053,
CVE-2019-14895, CVE-2019-2101, CVE-2019-15118, CVE-2018-20856, CVE-2018-14613,
CVE-2019-11477, CVE-2018-14614, CVE-2019-19534, CVE-2019-19066, CVE-2018-14609,
CVE-2019-17666, CVE-2019-19045, CVE-2019-14814, CVE-2019-17351, CVE-2019-15807,
CVE-2018-20669, CVE-2019-14763, CVE-2019-11135, CVE-2019-15117]
latest-version: kernel-4.4.0-1105.116
ubuntu-trusty-lts-xenial:
CVE-2016-10723: An issue was discovered in the Linux kernel through 4.17.2. Since
the page allocator does not yield CPU resources to the owner of the oom_lock mutex,
a local unprivileged user can trivially lock up the system forever by wasting
CPU resources from the page allocator (e.g., via concurrent page fault events)
when the global OOM killer is invoked.
CVE-2018-12126: In ONAP DCAE through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12127: In ONAP OOM through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12130: In ONAP CLI through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13093: An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel
through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow()
on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image.
This occurs because of a lack of proper validation that cached inodes are free
during allocation.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-13097: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect
user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).
CVE-2018-13098: An issue was discovered in fs/f2fs/inode.c in the Linux kernel through
4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a
modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel
through 4.17.3. A denial of service (out-of-bounds memory access and BUG) can
occur for a modified f2fs filesystem image in which an inline inode contains an
invalid reserved blkaddr.
CVE-2018-13100: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image,
as demonstrated by a divide-by-zero error.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14610: An issue was discovered in the Linux kernel through 4.17.10. There
is out-of-bounds access in write_extent_buffer() when mounting and operating a
crafted btrfs image, because of a lack of verification that each block group has
a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.
CVE-2018-14611: An issue was discovered in the Linux kernel through 4.17.10. There
is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image,
because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
CVE-2018-14612: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in btrfs_root_node() when mounting a crafted
btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups
in fs/btrfs/extent-tree.c, and a lack of empty-tree checks in check_leaf in fs/btrfs/tree-checker.c.
CVE-2018-14613: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in io_ctl_map_page() when mounting and operating
a crafted btrfs image, because of a lack of block group item validation in check_leaf_item
in fs/btrfs/tree-checker.c.
CVE-2018-14614: An issue was discovered in the Linux kernel through 4.17.10. There
is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when
mounting an f2fs image.
CVE-2018-14615: An issue was discovered in the Linux kernel through 4.17.10. There
is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting
an f2fs image, because a length value may be negative.
CVE-2018-14616: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c
when operating on a file in a corrupted f2fs image.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the
cleancache subsystem clears an inode after the final file truncation (removal).
The new file created with the same inode may contain leftover pages from cleancache
and the old file data instead of the new one.
CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+
shares mounted in different network namespaces at the same time can make bc_svc_process()
use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious
container user can cause a host kernel memory corruption and a system panic. Due
to the nature of the flaw, privilege escalation cannot be fully ruled out.
CVE-2018-19985: The function hso_get_config_data in drivers/net/usb/hso.c in the
Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses
it to index a small array, resulting in an object out-of-bounds (OOB) read that
potentially allows arbitrary read in the kernel address space.
CVE-2018-20169: An issue was discovered in the Linux kernel before 4.19.9. The USB
subsystem mishandles size checks during the reading of an extra descriptor, related
to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-20511: An issue was discovered in the Linux kernel before 4.18.11. The
ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain
sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route
dev and next fields via an SIOCFINDIPDDPRT ioctl call.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles
leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop
in update_blocked_averages) or possibly have unspecified other impact by inducing
a high load.
CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c,
there is an __blk_drain_queue() use-after-free because a certain error case is
mishandled.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2018-21008: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free
can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVE-2018-5383: Bluetooth firmware or operating system software drivers in macOS
versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions
before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters
used to generate public keys during a Diffie-Hellman key exchange, which may allow
a remote attacker to obtain the encryption key used by the device.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10126: A flaw was found in the Linux kernel. A heap based buffer overflow
in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c
might lead to memory corruption and possibly other consequences.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-10638: In the Linux kernel before 5.1.7, a device can be tracked by an
attacker using the IP ID values the kernel produces for connection-less protocols
(e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses,
it is possible to obtain hash collisions (of indices to the counter array) and
thereby obtain the hashing key (via enumeration). An attack may be conducted by
hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled
IP addresses.
CVE-2019-11085: Insufficient input validation in Kernel Mode Driver in Intel(R)
i915 Graphics for Linux before version 5.0 may allow an authenticated user to
potentially enable escalation of privilege via local access.
CVE-2019-11091: 'Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable
memory on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-1125: An information disclosure vulnerability exists when certain central
processing units (CPU) speculatively access memory, aka 'Windows Kernel Information
Disclosure Vulnerability'.
CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs
value was subject to an integer overflow in the Linux kernel when handling TCP
Selective Acknowledgments (SACKs).
CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation
in tcp_fragment in the Linux kernel could be fragmented when handling certain
TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this
to cause a denial of service.
CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is
hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues
significantly more than if a larger MSS were enforced. A remote attacker could
use this to cause a denial of service.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-11599: The coredump implementation in the Linux kernel before 5.0.10 does
not use locking or other mechanisms to prevent vma layout or vma flags changes
while it runs, which allows local users to obtain sensitive information, cause
a denial of service, or possibly have unspecified other impact by triggering a
race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c,
mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL
pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds()
in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service,
related to a use-after-free.
CVE-2019-11815: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero
out the unused memory region in the extent tree block, which might allow local
users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in
the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive
information from kernel stack memory via a HIDPCONNADD command, because a name
field may not end with a '\0' character.
CVE-2019-12818: An issue was discovered in the Linux kernel before 4.20.15. The
nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the
caller does not check for this, it will trigger a NULL pointer dereference. This
will cause denial of service. This affects nfc_llcp_build_gb in net/nfc/llcp_core.c.
CVE-2019-12819: An issue was discovered in the Linux kernel before 5.0. The function
__mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will
trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
CVE-2019-12984: A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target()
in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious
user-mode program that omits certain NFC attributes, leading to denial of service.
CVE-2019-13233: 'In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there
is a use-after-free for access to an LDT entry because of a race condition between
modify_ldt() and a #BR exception for an MPX bounds violation.'
CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c
mishandles the recording of the credentials of a process that wants to create
a ptrace relationship, which allows local users to obtain root access by leveraging
certain scenarios with a parent-child process relationship, where a parent drops
privileges and calls execve (potentially allowing control by an attacker). One
contributing factor is an object lifetime issue (which can also cause a panic).
Another contributing factor is incorrect marking of a ptrace relationship as privileged,
which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14283: 'In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c
does not validate the sect and head fields, as demonstrated by an integer overflow
and out-of-bounds read. It can be triggered by an unprivileged local user when
a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.'
CVE-2019-14284: 'In the Linux kernel before 5.2.3, drivers/block/floppy.c allows
a denial of service by setup_format_params division-by-zero. Two consecutive ioctls
can trigger the bug: the first one should set the drive geometry with .sect and
.rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation
should be called. It can be triggered by an unprivileged local user even when
a floppy disk has not been inserted.'
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14763: In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c
may potentially cause a deadlock with f_hid.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow
was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could be supplied
by a host user-space process. An unprivileged host user or process with access
to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in
a denial of service or potentially escalating privileges on the system.
CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x,
in the way Linux kernel's vhost functionality that translates virtqueue buffers
to IOVs, logged the buffer descriptors during migration. A privileged guest user
able to pass descriptors with invalid length to the host when migration is underway,
could use this flaw to increase their privileges on the host.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15214: An issue was discovered in the Linux kernel before 5.0.10. There
is a use-after-free in the sound subsystem because card disconnection causes certain
data structures to be deleted too early. This is related to sound/core/init.c
and sound/core/info.c.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15666: An issue was discovered in the Linux kernel before 5.0.19. There
is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial
of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory
validation.
CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c
when SAS expander discovery fails. This will cause a BUG and denial of service.
CVE-2019-15916: An issue was discovered in the Linux kernel before 5.0.1. There
is a memory leak in register_queue_kobjects() in net/core/net-sysfs.c, which will
cause denial of service.
CVE-2019-15918: An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate
in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely
updated after a change from smb30 to smb21.
CVE-2019-15921: An issue was discovered in the Linux kernel before 5.0.6. There
is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c.
CVE-2019-15924: An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module
in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference
because there is no -ENOMEM upon an alloc_workqueue failure.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16413: An issue was discovered in the Linux kernel before 5.0.4. The 9p
filesystem did not protect i_size_write() properly, which causes an i_size_read()
infinite loop and denial of service on SMP systems.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service, aka CID-07f12b26e21a.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service, aka CID-6caabe7f197d.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c
in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single
(a DMA function) from a stack variable. This could allow an attacker to trigger
a Denial of Service, exploitable if this driver is used on an architecture for
which this stack/DMA interaction has security relevance.
CVE-2019-17133: In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in
net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19046: A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
CVE-2019-19060: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-ab612b1daf41.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-19065: A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19075: A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c
in the Linux kernel before 5.3.8 allows attackers to cause a denial of service
(memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption). This affects the dce120_create_resource_pool() function
in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
CVE-2019-19083: Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3
has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry
for the Pivotal Platform
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2024: In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use
after free issue. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel.'
CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the
Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical
operations that can be also applied to the can_dlc field. The privileged user
"root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes
the data length code a higher value than the available CAN frame data size. In
combination with a configured checksum calculation where the result is stored
relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb
(e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can
cause a system crash. Because of a missing check, the CAN drivers may write arbitrary
content beyond the data registers in the CAN controller's I/O memory when processing
can-gw manipulated outgoing frames.
CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read()
in drivers/hid/hid-debug.c file which may enter an infinite loop with certain
parameters passed from a userspace. A local privileged user ("root") can cause
a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate
privileges was found in the mwifiex kernel module while connecting to a malicious
wireless network.
CVE-2019-3874: The SCTP socket buffer used by a userspace application is not accounted
by the cgroups subsystem. An attacker can use this flaw to cause a denial of service
attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation
that permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is administratively
granted ownership of the device, it may cause a system memory exhaustion and thus
a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in
Linux Kernel up to and including v5.1-rc6, while handling incoming packets in
handle_rx(). It could occur if one end sends packets faster than the other end
can process them. A guest user, maybe remote one, could use this flaw to stall
the vhost_net kernel thread, resulting in a DoS scenario.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9500: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality
is configured, a malicious event frame can be constructed to trigger an heap buffer
overflow in the brcmf_wowl_nd_results function.
CVE-2019-9503: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f
is vulnerable to a frame validation bypass. If the brcmfmac driver receives a
firmware event frame from a remote source, the is_wlc_event_frame function will
cause this frame to be discarded and unprocessed. If the driver receives the firmware
event frame from the host, the appropriate handler is called. This frame validation
can be bypassed if the bus used is USB (for instance by a wifi dongle). This can
allow firmware event frames from a remote source to be processed. In the worst
case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated
attacker may be able to execute arbitrary code on a vulnerable system. More typically,
this vulnerability will result in denial-of-service conditions.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled
instruction emulation for an L2 guest when nested virtualisation is enabled. Under
some circumstances, an L2 guest may trick the L0 guest into accessing sensitive
L1 resources that should be inaccessible to the L2 guest.
CVE-2020-7053: In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm
through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the
i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
CVE-2020-8428: fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky
use-after-free, which allows local users to cause a denial of service (OOPS) or
possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
One attack vector may be an open system call for a UNIX domain socket, if the
socket is being moved to a new parent directory and its old parent directory is
being removed.
cvelist: [CVE-2019-3701, CVE-2019-17056, CVE-2019-5108, CVE-2018-13093, CVE-2019-0154,
CVE-2018-16862, CVE-2019-19332, CVE-2019-15218, CVE-2019-15215, CVE-2019-19062,
CVE-2019-15220, CVE-2018-14612, CVE-2018-12207, CVE-2019-18786, CVE-2019-0155,
CVE-2019-17133, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091,
CVE-2019-15221, CVE-2019-15211, CVE-2019-11810, CVE-2019-16746, CVE-2019-19082,
CVE-2019-14816, CVE-2019-15090, CVE-2019-11884, CVE-2019-1125, CVE-2019-3900,
CVE-2018-19985, CVE-2019-19065, CVE-2019-14815, CVE-2018-13100, CVE-2019-16232,
CVE-2019-17055, CVE-2019-15214, CVE-2019-14615, CVE-2019-18885, CVE-2019-16413,
CVE-2019-15916, CVE-2018-21008, CVE-2018-5383, CVE-2020-2732, CVE-2019-15924,
CVE-2019-19083, CVE-2019-18683, CVE-2019-19767, CVE-2019-19524, CVE-2019-16995,
CVE-2019-15921, CVE-2019-11085, CVE-2019-19060, CVE-2018-14610, CVE-2019-14897,
CVE-2019-14821, CVE-2019-9503, CVE-2019-17075, CVE-2019-11599, CVE-2020-7053,
CVE-2019-9506, CVE-2018-20784, CVE-2018-20169, CVE-2019-17052, CVE-2019-15918,
CVE-2019-15291, CVE-2019-15217, CVE-2018-14616, CVE-2019-11833, CVE-2018-13097,
CVE-2018-13099, CVE-2019-15505, CVE-2019-15666, CVE-2019-15098, CVE-2019-11478,
CVE-2019-10638, CVE-2019-2024, CVE-2019-11815, CVE-2019-19063, CVE-2018-20511,
CVE-2019-10126, CVE-2019-12984, CVE-2019-3874, CVE-2019-14284, CVE-2018-13053,
CVE-2019-19078, CVE-2019-19965, CVE-2019-10207, CVE-2019-19071, CVE-2019-14835,
CVE-2019-16233, CVE-2019-16231, CVE-2019-3819, CVE-2019-11486, CVE-2019-19227,
CVE-2019-17054, CVE-2019-12819, CVE-2019-19052, CVE-2019-13233, CVE-2019-20096,
CVE-2019-11479, CVE-2019-13272, CVE-2019-19056, CVE-2019-18809, CVE-2019-19046,
CVE-2019-3882, CVE-2019-14901, CVE-2019-5489, CVE-2018-16884, CVE-2019-19068,
CVE-2020-8428, CVE-2019-19057, CVE-2019-19058, CVE-2019-9500, CVE-2019-16994,
CVE-2019-19051, CVE-2019-15099, CVE-2018-14615, CVE-2019-3846, CVE-2019-15212,
CVE-2019-19529, CVE-2018-13096, CVE-2018-14617, CVE-2019-16229, CVE-2018-20976,
CVE-2016-10723, CVE-2019-15538, CVE-2018-13098, CVE-2019-13631, CVE-2018-14611,
CVE-2019-12818, CVE-2019-11487, CVE-2019-14283, CVE-2019-19075, CVE-2019-17053,
CVE-2019-14895, CVE-2019-2101, CVE-2019-15118, CVE-2018-20856, CVE-2018-14613,
CVE-2019-11477, CVE-2018-14614, CVE-2019-19534, CVE-2019-19066, CVE-2018-14609,
CVE-2019-17666, CVE-2019-19045, CVE-2019-14814, CVE-2019-17351, CVE-2019-15807,
CVE-2018-20669, CVE-2019-14763, CVE-2019-11135, CVE-2019-15117]
latest-version: kernel-4.4.0-148.174~14.04.1
ubuntu-xenial-fips:
CVE-2016-10723: An issue was discovered in the Linux kernel through 4.17.2. Since
the page allocator does not yield CPU resources to the owner of the oom_lock mutex,
a local unprivileged user can trivially lock up the system forever by wasting
CPU resources from the page allocator (e.g., via concurrent page fault events)
when the global OOM killer is invoked.
CVE-2018-12126: In ONAP DCAE through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12127: In ONAP OOM through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12130: In ONAP CLI through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13093: An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel
through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow()
on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image.
This occurs because of a lack of proper validation that cached inodes are free
during allocation.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-13097: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect
user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).
CVE-2018-13098: An issue was discovered in fs/f2fs/inode.c in the Linux kernel through
4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a
modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel
through 4.17.3. A denial of service (out-of-bounds memory access and BUG) can
occur for a modified f2fs filesystem image in which an inline inode contains an
invalid reserved blkaddr.
CVE-2018-13100: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image,
as demonstrated by a divide-by-zero error.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14610: An issue was discovered in the Linux kernel through 4.17.10. There
is out-of-bounds access in write_extent_buffer() when mounting and operating a
crafted btrfs image, because of a lack of verification that each block group has
a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.
CVE-2018-14611: An issue was discovered in the Linux kernel through 4.17.10. There
is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image,
because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
CVE-2018-14612: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in btrfs_root_node() when mounting a crafted
btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups
in fs/btrfs/extent-tree.c, and a lack of empty-tree checks in check_leaf in fs/btrfs/tree-checker.c.
CVE-2018-14613: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in io_ctl_map_page() when mounting and operating
a crafted btrfs image, because of a lack of block group item validation in check_leaf_item
in fs/btrfs/tree-checker.c.
CVE-2018-14614: An issue was discovered in the Linux kernel through 4.17.10. There
is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when
mounting an f2fs image.
CVE-2018-14615: An issue was discovered in the Linux kernel through 4.17.10. There
is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting
an f2fs image, because a length value may be negative.
CVE-2018-14616: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c
when operating on a file in a corrupted f2fs image.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the
cleancache subsystem clears an inode after the final file truncation (removal).
The new file created with the same inode may contain leftover pages from cleancache
and the old file data instead of the new one.
CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+
shares mounted in different network namespaces at the same time can make bc_svc_process()
use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious
container user can cause a host kernel memory corruption and a system panic. Due
to the nature of the flaw, privilege escalation cannot be fully ruled out.
CVE-2018-19985: The function hso_get_config_data in drivers/net/usb/hso.c in the
Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses
it to index a small array, resulting in an object out-of-bounds (OOB) read that
potentially allows arbitrary read in the kernel address space.
CVE-2018-20169: An issue was discovered in the Linux kernel before 4.19.9. The USB
subsystem mishandles size checks during the reading of an extra descriptor, related
to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-20511: An issue was discovered in the Linux kernel before 4.18.11. The
ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain
sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route
dev and next fields via an SIOCFINDIPDDPRT ioctl call.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles
leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop
in update_blocked_averages) or possibly have unspecified other impact by inducing
a high load.
CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c,
there is an __blk_drain_queue() use-after-free because a certain error case is
mishandled.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2018-21008: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free
can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVE-2018-5383: Bluetooth firmware or operating system software drivers in macOS
versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions
before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters
used to generate public keys during a Diffie-Hellman key exchange, which may allow
a remote attacker to obtain the encryption key used by the device.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10126: A flaw was found in the Linux kernel. A heap based buffer overflow
in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c
might lead to memory corruption and possibly other consequences.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-10638: In the Linux kernel before 5.1.7, a device can be tracked by an
attacker using the IP ID values the kernel produces for connection-less protocols
(e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses,
it is possible to obtain hash collisions (of indices to the counter array) and
thereby obtain the hashing key (via enumeration). An attack may be conducted by
hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled
IP addresses.
CVE-2019-11085: Insufficient input validation in Kernel Mode Driver in Intel(R)
i915 Graphics for Linux before version 5.0 may allow an authenticated user to
potentially enable escalation of privilege via local access.
CVE-2019-11091: 'Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable
memory on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-1125: An information disclosure vulnerability exists when certain central
processing units (CPU) speculatively access memory, aka 'Windows Kernel Information
Disclosure Vulnerability'.
CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs
value was subject to an integer overflow in the Linux kernel when handling TCP
Selective Acknowledgments (SACKs).
CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation
in tcp_fragment in the Linux kernel could be fragmented when handling certain
TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this
to cause a denial of service.
CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is
hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues
significantly more than if a larger MSS were enforced. A remote attacker could
use this to cause a denial of service.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-11599: The coredump implementation in the Linux kernel before 5.0.10 does
not use locking or other mechanisms to prevent vma layout or vma flags changes
while it runs, which allows local users to obtain sensitive information, cause
a denial of service, or possibly have unspecified other impact by triggering a
race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c,
mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL
pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds()
in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service,
related to a use-after-free.
CVE-2019-11815: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero
out the unused memory region in the extent tree block, which might allow local
users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in
the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive
information from kernel stack memory via a HIDPCONNADD command, because a name
field may not end with a '\0' character.
CVE-2019-12818: An issue was discovered in the Linux kernel before 4.20.15. The
nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the
caller does not check for this, it will trigger a NULL pointer dereference. This
will cause denial of service. This affects nfc_llcp_build_gb in net/nfc/llcp_core.c.
CVE-2019-12819: An issue was discovered in the Linux kernel before 5.0. The function
__mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will
trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
CVE-2019-12984: A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target()
in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious
user-mode program that omits certain NFC attributes, leading to denial of service.
CVE-2019-13233: 'In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there
is a use-after-free for access to an LDT entry because of a race condition between
modify_ldt() and a #BR exception for an MPX bounds violation.'
CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c
mishandles the recording of the credentials of a process that wants to create
a ptrace relationship, which allows local users to obtain root access by leveraging
certain scenarios with a parent-child process relationship, where a parent drops
privileges and calls execve (potentially allowing control by an attacker). One
contributing factor is an object lifetime issue (which can also cause a panic).
Another contributing factor is incorrect marking of a ptrace relationship as privileged,
which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14283: 'In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c
does not validate the sect and head fields, as demonstrated by an integer overflow
and out-of-bounds read. It can be triggered by an unprivileged local user when
a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.'
CVE-2019-14284: 'In the Linux kernel before 5.2.3, drivers/block/floppy.c allows
a denial of service by setup_format_params division-by-zero. Two consecutive ioctls
can trigger the bug: the first one should set the drive geometry with .sect and
.rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation
should be called. It can be triggered by an unprivileged local user even when
a floppy disk has not been inserted.'
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14763: In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c
may potentially cause a deadlock with f_hid.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow
was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could be supplied
by a host user-space process. An unprivileged host user or process with access
to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in
a denial of service or potentially escalating privileges on the system.
CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x,
in the way Linux kernel's vhost functionality that translates virtqueue buffers
to IOVs, logged the buffer descriptors during migration. A privileged guest user
able to pass descriptors with invalid length to the host when migration is underway,
could use this flaw to increase their privileges on the host.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15214: An issue was discovered in the Linux kernel before 5.0.10. There
is a use-after-free in the sound subsystem because card disconnection causes certain
data structures to be deleted too early. This is related to sound/core/init.c
and sound/core/info.c.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15666: An issue was discovered in the Linux kernel before 5.0.19. There
is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial
of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory
validation.
CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c
when SAS expander discovery fails. This will cause a BUG and denial of service.
CVE-2019-15916: An issue was discovered in the Linux kernel before 5.0.1. There
is a memory leak in register_queue_kobjects() in net/core/net-sysfs.c, which will
cause denial of service.
CVE-2019-15918: An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate
in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely
updated after a change from smb30 to smb21.
CVE-2019-15921: An issue was discovered in the Linux kernel before 5.0.6. There
is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c.
CVE-2019-15924: An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module
in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference
because there is no -ENOMEM upon an alloc_workqueue failure.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16413: An issue was discovered in the Linux kernel before 5.0.4. The 9p
filesystem did not protect i_size_write() properly, which causes an i_size_read()
infinite loop and denial of service on SMP systems.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service, aka CID-07f12b26e21a.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service, aka CID-6caabe7f197d.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c
in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single
(a DMA function) from a stack variable. This could allow an attacker to trigger
a Denial of Service, exploitable if this driver is used on an architecture for
which this stack/DMA interaction has security relevance.
CVE-2019-17133: In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in
net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19046: A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
CVE-2019-19060: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-ab612b1daf41.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-19065: A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19075: A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c
in the Linux kernel before 5.3.8 allows attackers to cause a denial of service
(memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption). This affects the dce120_create_resource_pool() function
in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
CVE-2019-19083: Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3
has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry
for the Pivotal Platform
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2024: In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use
after free issue. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel.'
CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the
Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical
operations that can be also applied to the can_dlc field. The privileged user
"root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes
the data length code a higher value than the available CAN frame data size. In
combination with a configured checksum calculation where the result is stored
relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb
(e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can
cause a system crash. Because of a missing check, the CAN drivers may write arbitrary
content beyond the data registers in the CAN controller's I/O memory when processing
can-gw manipulated outgoing frames.
CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read()
in drivers/hid/hid-debug.c file which may enter an infinite loop with certain
parameters passed from a userspace. A local privileged user ("root") can cause
a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate
privileges was found in the mwifiex kernel module while connecting to a malicious
wireless network.
CVE-2019-3874: The SCTP socket buffer used by a userspace application is not accounted
by the cgroups subsystem. An attacker can use this flaw to cause a denial of service
attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation
that permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is administratively
granted ownership of the device, it may cause a system memory exhaustion and thus
a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in
Linux Kernel up to and including v5.1-rc6, while handling incoming packets in
handle_rx(). It could occur if one end sends packets faster than the other end
can process them. A guest user, maybe remote one, could use this flaw to stall
the vhost_net kernel thread, resulting in a DoS scenario.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9500: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality
is configured, a malicious event frame can be constructed to trigger an heap buffer
overflow in the brcmf_wowl_nd_results function.
CVE-2019-9503: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f
is vulnerable to a frame validation bypass. If the brcmfmac driver receives a
firmware event frame from a remote source, the is_wlc_event_frame function will
cause this frame to be discarded and unprocessed. If the driver receives the firmware
event frame from the host, the appropriate handler is called. This frame validation
can be bypassed if the bus used is USB (for instance by a wifi dongle). This can
allow firmware event frames from a remote source to be processed. In the worst
case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated
attacker may be able to execute arbitrary code on a vulnerable system. More typically,
this vulnerability will result in denial-of-service conditions.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled
instruction emulation for an L2 guest when nested virtualisation is enabled. Under
some circumstances, an L2 guest may trick the L0 guest into accessing sensitive
L1 resources that should be inaccessible to the L2 guest.
CVE-2020-7053: In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm
through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the
i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
CVE-2020-8428: fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky
use-after-free, which allows local users to cause a denial of service (OOPS) or
possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
One attack vector may be an open system call for a UNIX domain socket, if the
socket is being moved to a new parent directory and its old parent directory is
being removed.
cvelist: [CVE-2019-3701, CVE-2019-17056, CVE-2019-5108, CVE-2018-13093, CVE-2019-0154,
CVE-2018-16862, CVE-2019-19332, CVE-2019-15218, CVE-2019-15215, CVE-2019-19062,
CVE-2019-15220, CVE-2018-14612, CVE-2018-12207, CVE-2019-18786, CVE-2019-0155,
CVE-2019-17133, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091,
CVE-2019-15221, CVE-2019-15211, CVE-2019-11810, CVE-2019-16746, CVE-2019-19082,
CVE-2019-14816, CVE-2019-15090, CVE-2019-11884, CVE-2019-1125, CVE-2019-3900,
CVE-2018-19985, CVE-2019-19065, CVE-2019-14815, CVE-2018-13100, CVE-2019-16232,
CVE-2019-17055, CVE-2019-15214, CVE-2019-14615, CVE-2019-18885, CVE-2019-16413,
CVE-2019-15916, CVE-2018-21008, CVE-2018-5383, CVE-2020-2732, CVE-2019-15924,
CVE-2019-19083, CVE-2019-18683, CVE-2019-19767, CVE-2019-19524, CVE-2019-16995,
CVE-2019-15921, CVE-2019-11085, CVE-2019-19060, CVE-2018-14610, CVE-2019-14897,
CVE-2019-14821, CVE-2019-9503, CVE-2019-17075, CVE-2019-11599, CVE-2020-7053,
CVE-2019-9506, CVE-2018-20784, CVE-2018-20169, CVE-2019-17052, CVE-2019-15918,
CVE-2019-15291, CVE-2019-15217, CVE-2018-14616, CVE-2019-11833, CVE-2018-13097,
CVE-2018-13099, CVE-2019-15505, CVE-2019-15666, CVE-2019-15098, CVE-2019-11478,
CVE-2019-10638, CVE-2019-2024, CVE-2019-11815, CVE-2019-19063, CVE-2018-20511,
CVE-2019-10126, CVE-2019-12984, CVE-2019-3874, CVE-2019-14284, CVE-2018-13053,
CVE-2019-19078, CVE-2019-19965, CVE-2019-10207, CVE-2019-19071, CVE-2019-14835,
CVE-2019-16233, CVE-2019-16231, CVE-2019-3819, CVE-2019-11486, CVE-2019-19227,
CVE-2019-17054, CVE-2019-12819, CVE-2019-19052, CVE-2019-13233, CVE-2019-20096,
CVE-2019-11479, CVE-2019-13272, CVE-2019-19056, CVE-2019-18809, CVE-2019-19046,
CVE-2019-3882, CVE-2019-14901, CVE-2019-5489, CVE-2018-16884, CVE-2019-19068,
CVE-2020-8428, CVE-2019-19057, CVE-2019-19058, CVE-2019-9500, CVE-2019-16994,
CVE-2019-19051, CVE-2019-15099, CVE-2018-14615, CVE-2019-3846, CVE-2019-15212,
CVE-2019-19529, CVE-2018-13096, CVE-2018-14617, CVE-2019-16229, CVE-2018-20976,
CVE-2016-10723, CVE-2019-15538, CVE-2018-13098, CVE-2019-13631, CVE-2018-14611,
CVE-2019-12818, CVE-2019-11487, CVE-2019-14283, CVE-2019-19075, CVE-2019-17053,
CVE-2019-14895, CVE-2019-2101, CVE-2019-15118, CVE-2018-20856, CVE-2018-14613,
CVE-2019-11477, CVE-2018-14614, CVE-2019-19534, CVE-2019-19066, CVE-2018-14609,
CVE-2019-17666, CVE-2019-19045, CVE-2019-14814, CVE-2019-17351, CVE-2019-15807,
CVE-2018-20669, CVE-2019-14763, CVE-2019-11135, CVE-2019-15117]
latest-version: kernel-4.4.0-1027.32
ubuntu-xenial:
CVE-2016-10723: An issue was discovered in the Linux kernel through 4.17.2. Since
the page allocator does not yield CPU resources to the owner of the oom_lock mutex,
a local unprivileged user can trivially lock up the system forever by wasting
CPU resources from the page allocator (e.g., via concurrent page fault events)
when the global OOM killer is invoked.
CVE-2018-12126: In ONAP DCAE through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12127: In ONAP OOM through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12130: In ONAP CLI through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13093: An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel
through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow()
on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image.
This occurs because of a lack of proper validation that cached inodes are free
during allocation.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-13097: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect
user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).
CVE-2018-13098: An issue was discovered in fs/f2fs/inode.c in the Linux kernel through
4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a
modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel
through 4.17.3. A denial of service (out-of-bounds memory access and BUG) can
occur for a modified f2fs filesystem image in which an inline inode contains an
invalid reserved blkaddr.
CVE-2018-13100: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image,
as demonstrated by a divide-by-zero error.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14610: An issue was discovered in the Linux kernel through 4.17.10. There
is out-of-bounds access in write_extent_buffer() when mounting and operating a
crafted btrfs image, because of a lack of verification that each block group has
a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.
CVE-2018-14611: An issue was discovered in the Linux kernel through 4.17.10. There
is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image,
because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
CVE-2018-14612: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in btrfs_root_node() when mounting a crafted
btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups
in fs/btrfs/extent-tree.c, and a lack of empty-tree checks in check_leaf in fs/btrfs/tree-checker.c.
CVE-2018-14613: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in io_ctl_map_page() when mounting and operating
a crafted btrfs image, because of a lack of block group item validation in check_leaf_item
in fs/btrfs/tree-checker.c.
CVE-2018-14614: An issue was discovered in the Linux kernel through 4.17.10. There
is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when
mounting an f2fs image.
CVE-2018-14615: An issue was discovered in the Linux kernel through 4.17.10. There
is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting
an f2fs image, because a length value may be negative.
CVE-2018-14616: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c
when operating on a file in a corrupted f2fs image.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the
cleancache subsystem clears an inode after the final file truncation (removal).
The new file created with the same inode may contain leftover pages from cleancache
and the old file data instead of the new one.
CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+
shares mounted in different network namespaces at the same time can make bc_svc_process()
use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious
container user can cause a host kernel memory corruption and a system panic. Due
to the nature of the flaw, privilege escalation cannot be fully ruled out.
CVE-2018-19985: The function hso_get_config_data in drivers/net/usb/hso.c in the
Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses
it to index a small array, resulting in an object out-of-bounds (OOB) read that
potentially allows arbitrary read in the kernel address space.
CVE-2018-20169: An issue was discovered in the Linux kernel before 4.19.9. The USB
subsystem mishandles size checks during the reading of an extra descriptor, related
to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-20511: An issue was discovered in the Linux kernel before 4.18.11. The
ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain
sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route
dev and next fields via an SIOCFINDIPDDPRT ioctl call.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles
leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop
in update_blocked_averages) or possibly have unspecified other impact by inducing
a high load.
CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c,
there is an __blk_drain_queue() use-after-free because a certain error case is
mishandled.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2018-21008: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free
can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVE-2018-5383: Bluetooth firmware or operating system software drivers in macOS
versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions
before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters
used to generate public keys during a Diffie-Hellman key exchange, which may allow
a remote attacker to obtain the encryption key used by the device.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10126: A flaw was found in the Linux kernel. A heap based buffer overflow
in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c
might lead to memory corruption and possibly other consequences.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-10638: In the Linux kernel before 5.1.7, a device can be tracked by an
attacker using the IP ID values the kernel produces for connection-less protocols
(e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses,
it is possible to obtain hash collisions (of indices to the counter array) and
thereby obtain the hashing key (via enumeration). An attack may be conducted by
hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled
IP addresses.
CVE-2019-11085: Insufficient input validation in Kernel Mode Driver in Intel(R)
i915 Graphics for Linux before version 5.0 may allow an authenticated user to
potentially enable escalation of privilege via local access.
CVE-2019-11091: 'Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable
memory on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-1125: An information disclosure vulnerability exists when certain central
processing units (CPU) speculatively access memory, aka 'Windows Kernel Information
Disclosure Vulnerability'.
CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs
value was subject to an integer overflow in the Linux kernel when handling TCP
Selective Acknowledgments (SACKs).
CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation
in tcp_fragment in the Linux kernel could be fragmented when handling certain
TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this
to cause a denial of service.
CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is
hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues
significantly more than if a larger MSS were enforced. A remote attacker could
use this to cause a denial of service.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-11599: The coredump implementation in the Linux kernel before 5.0.10 does
not use locking or other mechanisms to prevent vma layout or vma flags changes
while it runs, which allows local users to obtain sensitive information, cause
a denial of service, or possibly have unspecified other impact by triggering a
race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c,
mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL
pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds()
in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service,
related to a use-after-free.
CVE-2019-11815: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero
out the unused memory region in the extent tree block, which might allow local
users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in
the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive
information from kernel stack memory via a HIDPCONNADD command, because a name
field may not end with a '\0' character.
CVE-2019-12818: An issue was discovered in the Linux kernel before 4.20.15. The
nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the
caller does not check for this, it will trigger a NULL pointer dereference. This
will cause denial of service. This affects nfc_llcp_build_gb in net/nfc/llcp_core.c.
CVE-2019-12819: An issue was discovered in the Linux kernel before 5.0. The function
__mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will
trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
CVE-2019-12984: A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target()
in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious
user-mode program that omits certain NFC attributes, leading to denial of service.
CVE-2019-13233: 'In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there
is a use-after-free for access to an LDT entry because of a race condition between
modify_ldt() and a #BR exception for an MPX bounds violation.'
CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c
mishandles the recording of the credentials of a process that wants to create
a ptrace relationship, which allows local users to obtain root access by leveraging
certain scenarios with a parent-child process relationship, where a parent drops
privileges and calls execve (potentially allowing control by an attacker). One
contributing factor is an object lifetime issue (which can also cause a panic).
Another contributing factor is incorrect marking of a ptrace relationship as privileged,
which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14283: 'In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c
does not validate the sect and head fields, as demonstrated by an integer overflow
and out-of-bounds read. It can be triggered by an unprivileged local user when
a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.'
CVE-2019-14284: 'In the Linux kernel before 5.2.3, drivers/block/floppy.c allows
a denial of service by setup_format_params division-by-zero. Two consecutive ioctls
can trigger the bug: the first one should set the drive geometry with .sect and
.rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation
should be called. It can be triggered by an unprivileged local user even when
a floppy disk has not been inserted.'
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14763: In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c
may potentially cause a deadlock with f_hid.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow
was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could be supplied
by a host user-space process. An unprivileged host user or process with access
to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in
a denial of service or potentially escalating privileges on the system.
CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x,
in the way Linux kernel's vhost functionality that translates virtqueue buffers
to IOVs, logged the buffer descriptors during migration. A privileged guest user
able to pass descriptors with invalid length to the host when migration is underway,
could use this flaw to increase their privileges on the host.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15214: An issue was discovered in the Linux kernel before 5.0.10. There
is a use-after-free in the sound subsystem because card disconnection causes certain
data structures to be deleted too early. This is related to sound/core/init.c
and sound/core/info.c.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15666: An issue was discovered in the Linux kernel before 5.0.19. There
is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial
of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory
validation.
CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c
when SAS expander discovery fails. This will cause a BUG and denial of service.
CVE-2019-15916: An issue was discovered in the Linux kernel before 5.0.1. There
is a memory leak in register_queue_kobjects() in net/core/net-sysfs.c, which will
cause denial of service.
CVE-2019-15918: An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate
in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely
updated after a change from smb30 to smb21.
CVE-2019-15921: An issue was discovered in the Linux kernel before 5.0.6. There
is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c.
CVE-2019-15924: An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module
in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference
because there is no -ENOMEM upon an alloc_workqueue failure.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16413: An issue was discovered in the Linux kernel before 5.0.4. The 9p
filesystem did not protect i_size_write() properly, which causes an i_size_read()
infinite loop and denial of service on SMP systems.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service, aka CID-07f12b26e21a.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service, aka CID-6caabe7f197d.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c
in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single
(a DMA function) from a stack variable. This could allow an attacker to trigger
a Denial of Service, exploitable if this driver is used on an architecture for
which this stack/DMA interaction has security relevance.
CVE-2019-17133: In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in
net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19046: A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
CVE-2019-19060: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-ab612b1daf41.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-19065: A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19075: A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c
in the Linux kernel before 5.3.8 allows attackers to cause a denial of service
(memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption). This affects the dce120_create_resource_pool() function
in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
CVE-2019-19083: Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3
has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry
for the Pivotal Platform
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2024: In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use
after free issue. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel.'
CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the
Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical
operations that can be also applied to the can_dlc field. The privileged user
"root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes
the data length code a higher value than the available CAN frame data size. In
combination with a configured checksum calculation where the result is stored
relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb
(e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can
cause a system crash. Because of a missing check, the CAN drivers may write arbitrary
content beyond the data registers in the CAN controller's I/O memory when processing
can-gw manipulated outgoing frames.
CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read()
in drivers/hid/hid-debug.c file which may enter an infinite loop with certain
parameters passed from a userspace. A local privileged user ("root") can cause
a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate
privileges was found in the mwifiex kernel module while connecting to a malicious
wireless network.
CVE-2019-3874: The SCTP socket buffer used by a userspace application is not accounted
by the cgroups subsystem. An attacker can use this flaw to cause a denial of service
attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation
that permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is administratively
granted ownership of the device, it may cause a system memory exhaustion and thus
a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in
Linux Kernel up to and including v5.1-rc6, while handling incoming packets in
handle_rx(). It could occur if one end sends packets faster than the other end
can process them. A guest user, maybe remote one, could use this flaw to stall
the vhost_net kernel thread, resulting in a DoS scenario.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9500: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality
is configured, a malicious event frame can be constructed to trigger an heap buffer
overflow in the brcmf_wowl_nd_results function.
CVE-2019-9503: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f
is vulnerable to a frame validation bypass. If the brcmfmac driver receives a
firmware event frame from a remote source, the is_wlc_event_frame function will
cause this frame to be discarded and unprocessed. If the driver receives the firmware
event frame from the host, the appropriate handler is called. This frame validation
can be bypassed if the bus used is USB (for instance by a wifi dongle). This can
allow firmware event frames from a remote source to be processed. In the worst
case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated
attacker may be able to execute arbitrary code on a vulnerable system. More typically,
this vulnerability will result in denial-of-service conditions.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled
instruction emulation for an L2 guest when nested virtualisation is enabled. Under
some circumstances, an L2 guest may trick the L0 guest into accessing sensitive
L1 resources that should be inaccessible to the L2 guest.
CVE-2020-7053: In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm
through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the
i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
CVE-2020-8428: fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky
use-after-free, which allows local users to cause a denial of service (OOPS) or
possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
One attack vector may be an open system call for a UNIX domain socket, if the
socket is being moved to a new parent directory and its old parent directory is
being removed.
cvelist: [CVE-2019-3701, CVE-2019-17056, CVE-2019-5108, CVE-2018-13093, CVE-2019-0154,
CVE-2018-16862, CVE-2019-19332, CVE-2019-15218, CVE-2019-15215, CVE-2019-19062,
CVE-2019-15220, CVE-2018-14612, CVE-2018-12207, CVE-2019-18786, CVE-2019-0155,
CVE-2019-17133, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091,
CVE-2019-15221, CVE-2019-15211, CVE-2019-11810, CVE-2019-16746, CVE-2019-19082,
CVE-2019-14816, CVE-2019-15090, CVE-2019-11884, CVE-2019-1125, CVE-2019-3900,
CVE-2018-19985, CVE-2019-19065, CVE-2019-14815, CVE-2018-13100, CVE-2019-16232,
CVE-2019-17055, CVE-2019-15214, CVE-2019-14615, CVE-2019-18885, CVE-2019-16413,
CVE-2019-15916, CVE-2018-21008, CVE-2018-5383, CVE-2020-2732, CVE-2019-15924,
CVE-2019-19083, CVE-2019-18683, CVE-2019-19767, CVE-2019-19524, CVE-2019-16995,
CVE-2019-15921, CVE-2019-11085, CVE-2019-19060, CVE-2018-14610, CVE-2019-14897,
CVE-2019-14821, CVE-2019-9503, CVE-2019-17075, CVE-2019-11599, CVE-2020-7053,
CVE-2019-9506, CVE-2018-20784, CVE-2018-20169, CVE-2019-17052, CVE-2019-15918,
CVE-2019-15291, CVE-2019-15217, CVE-2018-14616, CVE-2019-11833, CVE-2018-13097,
CVE-2018-13099, CVE-2019-15505, CVE-2019-15666, CVE-2019-15098, CVE-2019-11478,
CVE-2019-10638, CVE-2019-2024, CVE-2019-11815, CVE-2019-19063, CVE-2018-20511,
CVE-2019-10126, CVE-2019-12984, CVE-2019-3874, CVE-2019-14284, CVE-2018-13053,
CVE-2019-19078, CVE-2019-19965, CVE-2019-10207, CVE-2019-19071, CVE-2019-14835,
CVE-2019-16233, CVE-2019-16231, CVE-2019-3819, CVE-2019-11486, CVE-2019-19227,
CVE-2019-17054, CVE-2019-12819, CVE-2019-19052, CVE-2019-13233, CVE-2019-20096,
CVE-2019-11479, CVE-2019-13272, CVE-2019-19056, CVE-2019-18809, CVE-2019-19046,
CVE-2019-3882, CVE-2019-14901, CVE-2019-5489, CVE-2018-16884, CVE-2019-19068,
CVE-2020-8428, CVE-2019-19057, CVE-2019-19058, CVE-2019-9500, CVE-2019-16994,
CVE-2019-19051, CVE-2019-15099, CVE-2018-14615, CVE-2019-3846, CVE-2019-15212,
CVE-2019-19529, CVE-2018-13096, CVE-2018-14617, CVE-2019-16229, CVE-2018-20976,
CVE-2016-10723, CVE-2019-15538, CVE-2018-13098, CVE-2019-13631, CVE-2018-14611,
CVE-2019-12818, CVE-2019-11487, CVE-2019-14283, CVE-2019-19075, CVE-2019-17053,
CVE-2019-14895, CVE-2019-2101, CVE-2019-15118, CVE-2018-20856, CVE-2018-14613,
CVE-2019-11477, CVE-2018-14614, CVE-2019-19534, CVE-2019-19066, CVE-2018-14609,
CVE-2019-17666, CVE-2019-19045, CVE-2019-14814, CVE-2019-17351, CVE-2019-15807,
CVE-2018-20669, CVE-2019-14763, CVE-2019-11135, CVE-2019-15117]
latest-version: kernel-4.4.0-177.207
ubuntu-trusty-lts-xenial-aws:
CVE-2016-10723: An issue was discovered in the Linux kernel through 4.17.2. Since
the page allocator does not yield CPU resources to the owner of the oom_lock mutex,
a local unprivileged user can trivially lock up the system forever by wasting
CPU resources from the page allocator (e.g., via concurrent page fault events)
when the global OOM killer is invoked.
CVE-2018-12126: In ONAP DCAE through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12127: In ONAP OOM through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12130: In ONAP CLI through Dublin, by accessing an applicable port (30234,
30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains
full access to the respective ONAP services without any authentication. All ONAP
Operations Manager (OOM) setups are affected.
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the
Linux kernel through 4.17.3 has an integer overflow via a large relative timeout
because ktime_add_safe is not used.
CVE-2018-13093: An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel
through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow()
on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image.
This occurs because of a lack of proper validation that cached inodes are free
during allocation.
CVE-2018-13096: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. A denial of service (out-of-bounds memory access and BUG) can occur upon
encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-13097: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect
user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).
CVE-2018-13098: An issue was discovered in fs/f2fs/inode.c in the Linux kernel through
4.17.3. A denial of service (slab out-of-bounds read and BUG) can occur for a
modified f2fs filesystem image in which FI_EXTRA_ATTR is set in an inode.
CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel
through 4.17.3. A denial of service (out-of-bounds memory access and BUG) can
occur for a modified f2fs filesystem image in which an inline inode contains an
invalid reserved blkaddr.
CVE-2018-13100: An issue was discovered in fs/f2fs/super.c in the Linux kernel through
4.17.3, which does not properly validate secs_per_zone in a corrupted f2fs image,
as demonstrated by a divide-by-zero error.
CVE-2018-14609: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c
when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc
control has not been initialized.
CVE-2018-14610: An issue was discovered in the Linux kernel through 4.17.10. There
is out-of-bounds access in write_extent_buffer() when mounting and operating a
crafted btrfs image, because of a lack of verification that each block group has
a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.
CVE-2018-14611: An issue was discovered in the Linux kernel through 4.17.10. There
is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image,
because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
CVE-2018-14612: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in btrfs_root_node() when mounting a crafted
btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups
in fs/btrfs/extent-tree.c, and a lack of empty-tree checks in check_leaf in fs/btrfs/tree-checker.c.
CVE-2018-14613: An issue was discovered in the Linux kernel through 4.17.10. There
is an invalid pointer dereference in io_ctl_map_page() when mounting and operating
a crafted btrfs image, because of a lack of block group item validation in check_leaf_item
in fs/btrfs/tree-checker.c.
CVE-2018-14614: An issue was discovered in the Linux kernel through 4.17.10. There
is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when
mounting an f2fs image.
CVE-2018-14615: An issue was discovered in the Linux kernel through 4.17.10. There
is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting
an f2fs image, because a length value may be negative.
CVE-2018-14616: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c
when operating on a file in a corrupted f2fs image.
CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There
is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c
when opening a file (that is purportedly a hard link) in an hfs+ filesystem that
has malformed catalog data, and is mounted read-only without a metadata directory.
CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the
cleancache subsystem clears an inode after the final file truncation (removal).
The new file created with the same inode may contain leftover pages from cleancache
and the old file data instead of the new one.
CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+
shares mounted in different network namespaces at the same time can make bc_svc_process()
use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious
container user can cause a host kernel memory corruption and a system panic. Due
to the nature of the flaw, privilege escalation cannot be fully ruled out.
CVE-2018-19985: The function hso_get_config_data in drivers/net/usb/hso.c in the
Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses
it to index a small array, resulting in an object out-of-bounds (OOB) read that
potentially allows arbitrary read in the kernel address space.
CVE-2018-20169: An issue was discovered in the Linux kernel before 4.19.9. The USB
subsystem mishandles size checks during the reading of an extra descriptor, related
to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-20511: An issue was discovered in the Linux kernel before 4.18.11. The
ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain
sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route
dev and next fields via an SIOCFINDIPDDPRT ioctl call.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles
leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop
in update_blocked_averages) or possibly have unspecified other impact by inducing
a high load.
CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c,
there is an __blk_drain_queue() use-after-free because a certain error case is
mishandled.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2018-21008: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free
can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVE-2018-5383: Bluetooth firmware or operating system software drivers in macOS
versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions
before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters
used to generate public keys during a Diffie-Hellman key exchange, which may allow
a remote attacker to obtain the encryption key used by the device.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10126: A flaw was found in the Linux kernel. A heap based buffer overflow
in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c
might lead to memory corruption and possibly other consequences.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-10638: In the Linux kernel before 5.1.7, a device can be tracked by an
attacker using the IP ID values the kernel produces for connection-less protocols
(e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses,
it is possible to obtain hash collisions (of indices to the counter array) and
thereby obtain the hashing key (via enumeration). An attack may be conducted by
hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled
IP addresses.
CVE-2019-11085: Insufficient input validation in Kernel Mode Driver in Intel(R)
i915 Graphics for Linux before version 5.0 may allow an authenticated user to
potentially enable escalation of privilege via local access.
CVE-2019-11091: 'Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable
memory on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-1125: An information disclosure vulnerability exists when certain central
processing units (CPU) speculatively access memory, aka 'Windows Kernel Information
Disclosure Vulnerability'.
CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs
value was subject to an integer overflow in the Linux kernel when handling TCP
Selective Acknowledgments (SACKs).
CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation
in tcp_fragment in the Linux kernel could be fragmented when handling certain
TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this
to cause a denial of service.
CVE-2019-11479: Jonathan Looney discovered that the Linux kernel default MSS is
hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues
significantly more than if a larger MSS were enforced. A remote attacker could
use this to cause a denial of service.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-11599: The coredump implementation in the Linux kernel before 5.0.10 does
not use locking or other mechanisms to prevent vma layout or vma flags changes
while it runs, which allows local users to obtain sensitive information, cause
a denial of service, or possibly have unspecified other impact by triggering a
race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c,
mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.
CVE-2019-11810: An issue was discovered in the Linux kernel before 5.0.7. A NULL
pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds()
in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service,
related to a use-after-free.
CVE-2019-11815: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero
out the unused memory region in the extent tree block, which might allow local
users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in
the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive
information from kernel stack memory via a HIDPCONNADD command, because a name
field may not end with a '\0' character.
CVE-2019-12818: An issue was discovered in the Linux kernel before 4.20.15. The
nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the
caller does not check for this, it will trigger a NULL pointer dereference. This
will cause denial of service. This affects nfc_llcp_build_gb in net/nfc/llcp_core.c.
CVE-2019-12819: An issue was discovered in the Linux kernel before 5.0. The function
__mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will
trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
CVE-2019-12984: A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target()
in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious
user-mode program that omits certain NFC attributes, leading to denial of service.
CVE-2019-13233: 'In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there
is a use-after-free for access to an LDT entry because of a race condition between
modify_ldt() and a #BR exception for an MPX bounds violation.'
CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c
mishandles the recording of the credentials of a process that wants to create
a ptrace relationship, which allows local users to obtain root access by leveraging
certain scenarios with a parent-child process relationship, where a parent drops
privileges and calls execve (potentially allowing control by an attacker). One
contributing factor is an object lifetime issue (which can also cause a panic).
Another contributing factor is incorrect marking of a ptrace relationship as privileged,
which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14283: 'In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c
does not validate the sect and head fields, as demonstrated by an integer overflow
and out-of-bounds read. It can be triggered by an unprivileged local user when
a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.'
CVE-2019-14284: 'In the Linux kernel before 5.2.3, drivers/block/floppy.c allows
a denial of service by setup_format_params division-by-zero. Two consecutive ioctls
can trigger the bug: the first one should set the drive geometry with .sect and
.rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation
should be called. It can be triggered by an unprivileged local user even when
a floppy disk has not been inserted.'
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14763: In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c
may potentially cause a deadlock with f_hid.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow
was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could be supplied
by a host user-space process. An unprivileged host user or process with access
to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in
a denial of service or potentially escalating privileges on the system.
CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x,
in the way Linux kernel's vhost functionality that translates virtqueue buffers
to IOVs, logged the buffer descriptors during migration. A privileged guest user
able to pass descriptors with invalid length to the host when migration is underway,
could use this flaw to increase their privileges on the host.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15214: An issue was discovered in the Linux kernel before 5.0.10. There
is a use-after-free in the sound subsystem because card disconnection causes certain
data structures to be deleted too early. This is related to sound/core/init.c
and sound/core/info.c.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15666: An issue was discovered in the Linux kernel before 5.0.19. There
is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial
of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory
validation.
CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c
when SAS expander discovery fails. This will cause a BUG and denial of service.
CVE-2019-15916: An issue was discovered in the Linux kernel before 5.0.1. There
is a memory leak in register_queue_kobjects() in net/core/net-sysfs.c, which will
cause denial of service.
CVE-2019-15918: An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate
in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely
updated after a change from smb30 to smb21.
CVE-2019-15921: An issue was discovered in the Linux kernel before 5.0.6. There
is a memory leak issue when idr_alloc() fails in genl_register_family() in net/netlink/genetlink.c.
CVE-2019-15924: An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module
in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference
because there is no -ENOMEM upon an alloc_workqueue failure.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16413: An issue was discovered in the Linux kernel before 5.0.4. The 9p
filesystem did not protect i_size_write() properly, which causes an i_size_read()
infinite loop and denial of service on SMP systems.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service, aka CID-07f12b26e21a.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service, aka CID-6caabe7f197d.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c
in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single
(a DMA function) from a stack variable. This could allow an attacker to trigger
a Denial of Service, exploitable if this driver is used on an architecture for
which this stack/DMA interaction has security relevance.
CVE-2019-17133: In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in
net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19046: A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
CVE-2019-19060: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-ab612b1daf41.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in
the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free,
related to net namespace cleanup.
CVE-2019-19065: A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19075: A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c
in the Linux kernel before 5.3.8 allows attackers to cause a denial of service
(memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption). This affects the dce120_create_resource_pool() function
in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
CVE-2019-19083: Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3
has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry
for the Pivotal Platform
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2024: In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use
after free issue. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel.'
CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the
Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical
operations that can be also applied to the can_dlc field. The privileged user
"root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes
the data length code a higher value than the available CAN frame data size. In
combination with a configured checksum calculation where the result is stored
relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb
(e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can
cause a system crash. Because of a missing check, the CAN drivers may write arbitrary
content beyond the data registers in the CAN controller's I/O memory when processing
can-gw manipulated outgoing frames.
CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read()
in drivers/hid/hid-debug.c file which may enter an infinite loop with certain
parameters passed from a userspace. A local privileged user ("root") can cause
a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate
privileges was found in the mwifiex kernel module while connecting to a malicious
wireless network.
CVE-2019-3874: The SCTP socket buffer used by a userspace application is not accounted
by the cgroups subsystem. An attacker can use this flaw to cause a denial of service
attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.
CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation
that permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is administratively
granted ownership of the device, it may cause a system memory exhaustion and thus
a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in
Linux Kernel up to and including v5.1-rc6, while handling incoming packets in
handle_rx(). It could occur if one end sends packets faster than the other end
can process them. A guest user, maybe remote one, could use this flaw to stall
the vhost_net kernel thread, resulting in a DoS scenario.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9500: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff
is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality
is configured, a malicious event frame can be constructed to trigger an heap buffer
overflow in the brcmf_wowl_nd_results function.
CVE-2019-9503: The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f
is vulnerable to a frame validation bypass. If the brcmfmac driver receives a
firmware event frame from a remote source, the is_wlc_event_frame function will
cause this frame to be discarded and unprocessed. If the driver receives the firmware
event frame from the host, the appropriate handler is called. This frame validation
can be bypassed if the bus used is USB (for instance by a wifi dongle). This can
allow firmware event frames from a remote source to be processed. In the worst
case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated
attacker may be able to execute arbitrary code on a vulnerable system. More typically,
this vulnerability will result in denial-of-service conditions.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled
instruction emulation for an L2 guest when nested virtualisation is enabled. Under
some circumstances, an L2 guest may trick the L0 guest into accessing sensitive
L1 resources that should be inaccessible to the L2 guest.
CVE-2020-7053: In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm
through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the
i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
CVE-2020-8428: fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky
use-after-free, which allows local users to cause a denial of service (OOPS) or
possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
One attack vector may be an open system call for a UNIX domain socket, if the
socket is being moved to a new parent directory and its old parent directory is
being removed.
cvelist: [CVE-2019-3701, CVE-2019-17056, CVE-2019-5108, CVE-2018-13093, CVE-2019-0154,
CVE-2018-16862, CVE-2019-19332, CVE-2019-15218, CVE-2019-15215, CVE-2019-19062,
CVE-2019-15220, CVE-2018-14612, CVE-2018-12207, CVE-2019-18786, CVE-2019-0155,
CVE-2019-17133, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091,
CVE-2019-15221, CVE-2019-15211, CVE-2019-11810, CVE-2019-16746, CVE-2019-19082,
CVE-2019-14816, CVE-2019-15090, CVE-2019-11884, CVE-2019-1125, CVE-2019-3900,
CVE-2018-19985, CVE-2019-19065, CVE-2019-14815, CVE-2018-13100, CVE-2019-16232,
CVE-2019-17055, CVE-2019-15214, CVE-2019-14615, CVE-2019-18885, CVE-2019-16413,
CVE-2019-15916, CVE-2018-21008, CVE-2018-5383, CVE-2020-2732, CVE-2019-15924,
CVE-2019-19083, CVE-2019-18683, CVE-2019-19767, CVE-2019-19524, CVE-2019-16995,
CVE-2019-15921, CVE-2019-11085, CVE-2019-19060, CVE-2018-14610, CVE-2019-14897,
CVE-2019-14821, CVE-2019-9503, CVE-2019-17075, CVE-2019-11599, CVE-2020-7053,
CVE-2019-9506, CVE-2018-20784, CVE-2018-20169, CVE-2019-17052, CVE-2019-15918,
CVE-2019-15291, CVE-2019-15217, CVE-2018-14616, CVE-2019-11833, CVE-2018-13097,
CVE-2018-13099, CVE-2019-15505, CVE-2019-15666, CVE-2019-15098, CVE-2019-11478,
CVE-2019-10638, CVE-2019-2024, CVE-2019-11815, CVE-2019-19063, CVE-2018-20511,
CVE-2019-10126, CVE-2019-12984, CVE-2019-3874, CVE-2019-14284, CVE-2018-13053,
CVE-2019-19078, CVE-2019-19965, CVE-2019-10207, CVE-2019-19071, CVE-2019-14835,
CVE-2019-16233, CVE-2019-16231, CVE-2019-3819, CVE-2019-11486, CVE-2019-19227,
CVE-2019-17054, CVE-2019-12819, CVE-2019-19052, CVE-2019-13233, CVE-2019-20096,
CVE-2019-11479, CVE-2019-13272, CVE-2019-19056, CVE-2019-18809, CVE-2019-19046,
CVE-2019-3882, CVE-2019-14901, CVE-2019-5489, CVE-2018-16884, CVE-2019-19068,
CVE-2020-8428, CVE-2019-19057, CVE-2019-19058, CVE-2019-9500, CVE-2019-16994,
CVE-2019-19051, CVE-2019-15099, CVE-2018-14615, CVE-2019-3846, CVE-2019-15212,
CVE-2019-19529, CVE-2018-13096, CVE-2018-14617, CVE-2019-16229, CVE-2018-20976,
CVE-2016-10723, CVE-2019-15538, CVE-2018-13098, CVE-2019-13631, CVE-2018-14611,
CVE-2019-12818, CVE-2019-11487, CVE-2019-14283, CVE-2019-19075, CVE-2019-17053,
CVE-2019-14895, CVE-2019-2101, CVE-2019-15118, CVE-2018-20856, CVE-2018-14613,
CVE-2019-11477, CVE-2018-14614, CVE-2019-19534, CVE-2019-19066, CVE-2018-14609,
CVE-2019-17666, CVE-2019-19045, CVE-2019-14814, CVE-2019-17351, CVE-2019-15807,
CVE-2018-20669, CVE-2019-14763, CVE-2019-11135, CVE-2019-15117]
latest-version: kernel-4.4.0-1037.40

KernelCare

unread,
Apr 28, 2020, 11:24:14 AM4/28/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-trusty:
CVE-2016-10905: An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before
4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
CVE-2017-18232: The Serial Attached SCSI (SAS) implementation in the Linux kernel
through 4.15.9 mishandles a mutex within libsas, which allows local users to cause
a denial of service (deadlock) by triggering certain error-handling code.
CVE-2017-18509: An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel
before 4.11. By setting a specific socket option, an attacker can control a pointer
in kernel land and cause an inet_csk_listen_stop general protection fault, or
potentially execute arbitrary code under certain circumstances. The issue can
be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN
capability) or after namespace unsharing. This occurs because sk_type and protocol
are not checked in the appropriate part of the ip6_mroute_* functions.
CVE-2017-18551: An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux
kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated.
CVE-2018-10938: A flaw was found in the Linux kernel present since v4.0-rc1 and
through v4.13-rc4. A crafted network packet sent remotely by an attacker may force
the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c
leading to a denial-of-service. A certain non-default configuration of LSM (Linux
Security Module) and NetLabel should be set up on a system before an attacker
could leverage this flaw.
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-20784: In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles
leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop
in update_blocked_averages) or possibly have unspecified other impact by inducing
a high load.
CVE-2018-20856: An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c,
there is an __blk_drain_queue() use-after-free because a certain error case is
mishandled.
CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in
the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi
driver may allow attackers to cause a denial of service or possibly have unspecified
other impact.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2018-21008: An issue was discovered in the Linux kernel before 4.16.7. A use-after-free
can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10142: A flaw was found in the Linux kernel's freescale hypervisor manager
implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed
to an ioctl was incorrectly validated and used in size calculations for the page
size calculation. An attacker can use this flaw to crash the system, corrupt memory,
or create other adverse security affects.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero
out the unused memory region in the extent tree block, which might allow local
users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in
the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive
information from kernel stack memory via a HIDPCONNADD command, because a name
field may not end with a '\0' character.
CVE-2019-12818: An issue was discovered in the Linux kernel before 4.20.15. The
nfc_llcp_build_tlv function in net/nfc/llcp_commands.c may return NULL. If the
caller does not check for this, it will trigger a NULL pointer dereference. This
will cause denial of service. This affects nfc_llcp_build_gb in net/nfc/llcp_core.c.
CVE-2019-12819: An issue was discovered in the Linux kernel before 5.0. The function
__mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will
trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14283: 'In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c
does not validate the sect and head fields, as demonstrated by an integer overflow
and out-of-bounds read. It can be triggered by an unprivileged local user when
a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.'
CVE-2019-14284: 'In the Linux kernel before 5.2.3, drivers/block/floppy.c allows
a denial of service by setup_format_params division-by-zero. Two consecutive ioctls
can trigger the bug: the first one should set the drive geometry with .sect and
.rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation
should be called. It can be triggered by an unprivileged local user even when
a floppy disk has not been inserted.'
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could be supplied
by a host user-space process. An unprivileged host user or process with access
to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in
a denial of service or potentially escalating privileges on the system.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15926: An issue was discovered in the Linux kernel before 5.2.3. Out of
bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and
ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
CVE-2019-16413: An issue was discovered in the Linux kernel before 5.0.4. The 9p
filesystem did not protect i_size_write() properly, which causes an i_size_read()
infinite loop and denial of service on SMP systems.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2101: In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation.
CVE-2019-2215: A use-after-free in binder.c allows an elevation of privilege from
an application to the Linux Kernel. No user interaction is required to exploit
this vulnerability, however exploitation does require either the installation
of a malicious local application or a separate vulnerability in a network facing
application.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled
instruction emulation for an L2 guest when nested virtualisation is enabled. Under
some circumstances, an L2 guest may trick the L0 guest into accessing sensitive
L1 resources that should be inaccessible to the L2 guest.
CVE-2020-8428: fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky
use-after-free, which allows local users to cause a denial of service (OOPS) or
possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9.
One attack vector may be an open system call for a UNIX domain socket, if the
socket is being moved to a new parent directory and its old parent directory is
being removed.
cvelist: [CVE-2019-11833, CVE-2019-17056, CVE-2018-21008, CVE-2019-5108, CVE-2019-19068,
CVE-2020-2732, CVE-2020-8428, CVE-2019-19057, CVE-2019-0154, CVE-2019-19332, CVE-2019-18683,
CVE-2019-19051, CVE-2019-15098, CVE-2019-15505, CVE-2019-15926, CVE-2019-15215,
CVE-2019-19062, CVE-2019-15220, CVE-2019-19063, CVE-2019-19524, CVE-2018-12207,
CVE-2018-20961, CVE-2017-18509, CVE-2019-0155, CVE-2018-20976, CVE-2019-17133,
CVE-2019-16995, CVE-2019-15117, CVE-2017-18232, CVE-2019-0136, CVE-2019-13631,
CVE-2019-14284, CVE-2019-12818, CVE-2019-10142, CVE-2019-10207, CVE-2019-19965,
CVE-2019-15221, CVE-2019-11487, CVE-2019-15211, CVE-2019-17053, CVE-2019-16746,
CVE-2019-14283, CVE-2019-14895, CVE-2019-14816, CVE-2019-15118, CVE-2019-2215,
CVE-2019-2101, CVE-2019-14821, CVE-2018-20856, CVE-2019-19227, CVE-2019-17054,
CVE-2019-12819, CVE-2019-14897, CVE-2019-19052, CVE-2019-11884, CVE-2019-20096,
CVE-2018-10938, CVE-2019-17075, CVE-2017-18551, CVE-2019-19534, CVE-2019-19066,
CVE-2018-20784, CVE-2019-17666, CVE-2019-17052, CVE-2019-16413, CVE-2019-17351,
CVE-2019-14814, CVE-2019-19056, CVE-2019-17055, CVE-2019-15291, CVE-2016-10905,
CVE-2019-15217, CVE-2019-14615, CVE-2019-18885, CVE-2019-11135, CVE-2019-14901]
latest-version: kernel-3.13.0-175.226
Reply all
Reply to author
Forward
0 new messages