Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19537

Опубликовано: 12 авг. 2019
Источник: redhat
CVSS3: 4.2

Описание

In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.

A flaw was found in the Linux kernel, where there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer. An attacker who can hotplug at least two devices of this class can cause a use-after-free situation.

Меры по смягчению последствий

Many Character devices can trigger this flaw as they leverage the lower levels of the USB subsystem. The safest method that I have found would be to disable USB ports that are able to be attacked using this method, disable them first by disallowing them from waking up from low-power states with the command (Replace X with the port number available). echo disabled >> /sys/bus/usb/devices/usbX/power/wakeup The system must also disable the specific ports power after with the command: echo suspend | sudo tee /sys/bus/usb/devices/usbX/power/level This change not persist through system reboots and must be applied at each reboot to be effective.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelOut of support scope
Red Hat Enterprise Linux 6kernelWill not fix
Red Hat Enterprise Linux 7kernel-altWill not fix
Red Hat Enterprise MRG 2kernel-rtWill not fix
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2020:406229.09.2020
Red Hat Enterprise Linux 7kernelFixedRHSA-2020:406029.09.2020
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2020:460904.11.2020
Red Hat Enterprise Linux 8kernelFixedRHSA-2020:443104.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1783561kernel: race condition caused by a malicious USB device in the USB character device driver layer

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
больше 5 лет назад

In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.

CVSS3: 4.2
nvd
больше 5 лет назад

In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.

CVSS3: 4.2
debian
больше 5 лет назад

In the Linux kernel before 5.2.10, there is a race condition bug that ...

github
около 3 лет назад

In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.

CVSS3: 4.2
fstec
почти 6 лет назад

Уязвимость драйвера drivers/usb/core/file.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

4.2 Medium

CVSS3