CVE-2019-2101 PUBLISHED

In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.

EPSS 0.10% · 28.5th percentile

Risk Scores

EPSS Score
0.10%
28.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-aws4.4.0-1035.44, 4.4.0-1003.12, 4.4.0-1004.13
Ubuntu:18.04:LTSlinux-oem4.15.0-1013.16, 4.15.0-1015.18, 4.15.0-1017.20
Ubuntu:22.04:LTSlinux-riscv5.15.0-1027.31, 0, 5.13.0-1004.4
Ubuntu:18.04:LTSlinux-gcp4.15.0-1018.19, 4.15.0-1026.27, 4.15.0-1025.26
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1047.51~14.04.1, 4.15.0-1049.54~14.04.1, 4.15.0-1050.55~14.04.1
Ubuntu:16.04:LTSlinux-oracle4.15.0-1011.13~16.04.1, 4.15.0-1018.20~16.04.1, 4.15.0-1017.19~16.04.2
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips0, 4.15.0-1001.1
Ubuntu:20.04:LTSlinux-gke5.4.0-1101.108, 5.4.0-1105.112, 5.4.0-1104.111
Ubuntu:Pro:14.04:LTSlinux3.13.0-88.135, 3.13.0-91.138, 3.13.0-92.139
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-137.163~14.04.1, 0, 4.4.0-13.29~14.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips0, 4.15.0-2000.4
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1044.46~16.04.1, 4.15.0-1043.45~16.04.1, 4.15.0-1041.43~16.04.1
Ubuntu:18.04:LTSlinux-raspi24.15.0-1022.24, 4.15.0-1031.33, 4.15.0-1030.32
Ubuntu:18.04:LTSlinux-snapdragon4.4.0-1079.84, 4.15.0-1054.58, 4.15.0-1053.57
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1037.39, 0, 4.15.0-1036.38
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips0, 4.4.0-1006.6, 4.4.0-1005.5
Ubuntu:14.04:LTSlinux-aws4.4.0-1002.2, 4.4.0-1005.5, 4.4.0-1006.6
Ubuntu:18.04:LTSlinux-hwe4.18.0-21.22~18.04.1, 4.18.0-25.26~18.04.1, 4.18.0-24.25~18.04.1
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1079.84, 4.4.0-1078.83, 4.4.0-1077.82
Ubuntu:18.04:LTSlinux4.13.0-32.35, 4.15.0-55.60, 4.15.0-54.58

…and 16 more

Timeline

References

Open in Interactive Console →