cbcvebase.
CVE-2018-19824
published 2018-12-03

CVE-2018-19824: In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero…

PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.56%
43.7th percentile
In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.19.9-1 (bookworm)linux 4.19.9-1 (bookworm)
googleandroid
linuxlinux_kernel<= 4.19.6
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 4.19.9-14.19.9-1
linuxlinux_kernel>= 0 < 3.13.0-168.2183.13.0-168.218
linuxlinux_kernel>= 0 < 4.4.0-142.1684.4.0-142.168
linuxlinux_kernel>= 0 < 4.15.0-47.504.15.0-47.50

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.