CVE-2019-19536 PUBLISHED

In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_pro.c driver, aka CID-ead16e53c2f0.

EPSS 0.08% · 23.7th percentile

Risk Scores

EPSS Score
0.08%
23.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-oracle4.15.0-1025.28~16.04.1, 4.15.0-1023.26~16.04.1, 4.15.0-1022.25~16.04.1
Ubuntu:16.04:LTSlinux-kvm4.4.0-1035.41, 4.4.0-1012.17, 4.4.0-1013.18
Ubuntu:18.04:LTSlinux-oem4.15.0-1006.9, 4.15.0-1021.24, 4.15.0-1024.29
Ubuntu:18.04:LTSlinux-gke-5.05.0.0-1017.17~18.04.1, 5.0.0-1015.15~18.04.1, 0
Ubuntu:16.04:LTSlinux4.2.0-16.19, 4.4.0-165.193, 4.4.0-164.192
Ubuntu:16.04:LTSlinux-hwe-edge4.15.0-23.25~16.04.1, 4.15.0-22.24~16.04.1, 4.15.0-20.21~16.04.1
Ubuntu:18.04:LTSlinux4.15.0-64.73, 4.15.0-55.60, 4.15.0-58.64
Ubuntu:16.04:LTSlinux-raspi24.4.0-1046.53, 4.4.0-1044.51, 4.4.0-1042.49
Ubuntu:18.04:LTSlinux-aws4.15.0-1016.16, 4.15.0-1050.52, 4.15.0-1048.50
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1068.71+cvm1.1, 5.4.0-1103.109+cvm1.1, 5.4.0-1100.106+cvm1.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips4.15.0-1001.1, 0
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1032.34~16.04.1, 4.15.0-1031.33~16.04.1, 4.15.0-1030.31~16.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips0, 4.15.0-1002.2
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-16.17~18.04.1, 5.0.0-17.18~18.04.1, 5.0.0-19.20~18.04.1
Ubuntu:16.04:LTSlinux-hwe0, 4.15.0-64.73~16.04.1, 4.15.0-62.69~16.04.1
Ubuntu:22.04:LTSlinux-riscv5.13.0-1010.11+22.04.1, 5.15.0-1005.5, 5.15.0-1016.18
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1015.16~18.04.1, 4.18.0-1013.14~18.04.1, 4.18.0-1012.13~18.04.1
Ubuntu:16.04:LTSlinux-aws4.4.0-1069.79, 4.4.0-1072.82, 4.4.0-1073.83
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1036.38, 4.15.0-1037.39, 4.15.0-1040.42

…and 23 more

Timeline

References

Open in Interactive Console →