Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9456

Опубликовано: 03 сент. 2019
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

A flaw was found in the USB monitor driver of the Linux kernel. This flaw allows an attacker with physical access to the system to crash the system or potentially escalate their privileges.

Отчет

This issue is rated as having Low impact because of the need of physical access and debugfs mounted.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernel-altFix deferred
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise MRG 2kernel-rtOut of support scope
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:204307.08.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:202906.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1819156kernel: OOB write due to missing bounds check leads to local privilege escalation

EPSS

Процентиль: 38%
0.00159
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 6 лет назад

In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
nvd
почти 6 лет назад

In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
debian
почти 6 лет назад

In the Android kernel in Pixel C USB monitor driver there is a possibl ...

CVSS3: 6.7
github
около 3 лет назад

In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

oracle-oval
почти 4 года назад

ELSA-2021-9442: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 38%
0.00159
Низкий

6.7 Medium

CVSS3