CVE-2019-19528 PUBLISHED

In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.

EPSS 0.12% · 30.3th percentile

Risk Scores

EPSS Score
0.12%
30.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1006.7~18.04.1, 4.18.0-1007.8~18.04.1, 4.18.0-1005.6~18.04.1
Ubuntu:18.04:LTSlinux-aws-5.00, 5.0.0-1021.24~18.04.1
Ubuntu:18.04:LTSlinux-raspi24.15.0-1012.13, 4.15.0-1013.14, 4.15.0-1011.12
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:20.04:LTSlinux-raspi25.3.0-1017.19, 5.4.0-1006.6, 0
Ubuntu:Pro:14.04:LTSlinux3.13.0-142.191, 3.13.0-141.190, 3.13.0-139.188
Ubuntu:16.04:LTSlinux4.4.0-14.30, 0, 4.2.0-16.19
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:18.04:LTSlinux-gcp4.15.0-1017.18, 4.15.0-1018.19, 4.15.0-1019.20
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1036.38~14.04.2, 4.15.0-1035.36~14.04.2, 4.15.0-1032.33~14.04.2
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1048.50~16.04.1, 4.15.0-1054.56~16.04.1, 4.15.0-1052.54~16.04.1
Ubuntu:16.04:LTSlinux-raspi24.4.0-1123.132, 4.4.0-1124.133, 0
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-97.120~14.04.1, 4.4.0-62.83~14.04.1, 4.4.0-63.84~14.04.2
Ubuntu:18.04:LTSlinux-gke-5.05.0.0-1022.22~18.04.3, 5.0.0-1023.23~18.04.2, 5.0.0-1025.26~18.04.1
Ubuntu:18.04:LTSlinux-azure-edge0, 4.18.0-1006.6~18.04.1, 4.18.0-1007.7~18.04.1
Ubuntu:18.04:LTSlinux-oem4.15.0-1026.31, 4.15.0-1028.33, 4.15.0-1030.35
Ubuntu:16.04:LTSlinux-gcp4.15.0-1040.42~16.04.1, 4.13.0-1013.17, 4.13.0-1015.19
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1057.62, 4.15.0-1055.59, 4.15.0-1054.58
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips4.15.0-1002.2, 0
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-19.20~18.04.1, 5.3.0-22.24~18.04.1, 5.3.0-23.25~18.04.1

…and 26 more

Timeline

References

Open in Interactive Console →