614
VMScore

CVE-2019-19529

Published: 03/12/2019 Updated: 12/08/2020
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.3 | Impact Score: 5.9 | Exploitability Score: 0.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

In the Linux kernel prior to 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c driver, aka CID-4d6636498c41.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 14.04

canonical ubuntu linux 19.10

Mailing Lists

Hi! More CVEs for bugs in Linux kernel USB drivers that can be triggered by an external malicious USB device Found with syzkaller [1] This time no obvious DoSs (see the discussions here [2, 3]): mostly UAFs, some info-leaks All of these bugs have been fixed upstream (but many other syzbot USB bugs are still not fixed [4]) [1] githubc ...