cbcvebase.
CVE-2019-11884
published 2019-05-10

CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information…

low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.19.37-4 (bookworm)linux 4.19.37-4 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel< 5.0.155.0.15
linuxlinux_kernel>= 0 < 4.19.37-44.19.37-4
linuxlinux_kernel>= 0 < 4.19.37-44.19.37-4
linuxlinux_kernel>= 0 < 4.19.37-44.19.37-4
linuxlinux_kernel>= 0 < 4.19.37-44.19.37-4
linuxlinux_kernel>= 0 < 4.4.0-157.1854.4.0-157.185
linuxlinux_kernel>= 0 < 4.15.0-55.604.15.0-55.60
linuxlinux_kernel>= 0 < 4.15.0-99.1004.15.0-99.100
opensuseleap
opensuseleap
opensuseleap
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv8.1HIGH