CVE-2019-19524 PUBLISHED

In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.

EPSS 0.04% · 12.7th percentile

Risk Scores

EPSS Score
0.04%
12.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1049.52, 4.15.0-1048.51, 4.15.0-1046.49
Ubuntu:16.04:LTSlinux-azure4.15.0-1049.54, 4.15.0-1050.55, 4.15.0-1051.56
Ubuntu:18.04:LTSlinux-gcp5.0.0-1025.26~18.04.1, 4.15.0-1014.14, 4.15.0-1032.34
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1002.2, 4.4.0-1005.5, 4.4.0-1006.6
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1031.32~14.04.1, 0, 4.15.0-1023.24~14.04.1
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1082.87, 4.4.0-1081.86, 4.4.0-1079.84
Ubuntu:16.04:LTSlinux-raspi24.4.0-1050.57, 4.4.0-1085.93, 4.4.0-1086.94
Ubuntu:20.04:LTSlinux-gke5.4.0-1042.44, 5.4.0-1039.41, 5.4.0-1037.39
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips0, 4.15.0-2000.4
Ubuntu:22.04:LTSlinux-riscv5.15.0-1008.8, 5.15.0-1028.32, 5.15.0-1027.31
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips4.15.0-1002.2, 0
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1085.90+cvm1.1, 5.4.0-1103.109+cvm1.1, 5.4.0-1065.68+cvm2.1
Ubuntu:18.04:LTSlinux-oracle4.15.0-1026.29, 4.15.0-1025.28, 4.15.0-1023.26
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1045.48, 0, 4.4.0-1034.37
Ubuntu:18.04:LTSlinux4.15.0-55.60, 4.15.0-52.56, 4.15.0-51.55
Ubuntu:18.04:LTSlinux-azure-5.35.3.0-1007.8~18.04.1, 0, 5.3.0-1008.9~18.04.1
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:18.04:LTSlinux-hwe4.18.0-16.17~18.04.1, 4.18.0-18.19~18.04.1, 4.18.0-20.21~18.04.1
Ubuntu:18.04:LTSlinux-raspi24.15.0-1028.30, 4.15.0-1027.29, 4.15.0-1026.28
Ubuntu:18.04:LTSlinux-kvm4.15.0-1003.3, 0, 4.15.0-1002.2

…and 29 more

Timeline

References

Open in Interactive Console →