CVE-2019-18675
published 2019-11-25CVE-2019-18675: The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.53%
41.4th percentile
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.16.16-1 (bookworm) | linux 4.16.16-1 (bookworm) |
| linux | linux_kernel | < 3.16.60 | 3.16.60 |
| linux | linux_kernel | >= 0 < 4.16.16-1 | 4.16.16-1 |
| linux | linux_kernel | >= 0 < 4.16.16-1 | 4.16.16-1 |
| linux | linux_kernel | >= 0 < 4.16.16-1 | 4.16.16-1 |
| linux | linux_kernel | >= 0 < 4.16.16-1 | 4.16.16-1 |
| linux | linux_kernel | >= 3.17 < 3.18.113 | 3.18.113 |
| linux | linux_kernel | >= 3.19 < 4.4.137 | 4.4.137 |
| linux | linux_kernel | >= 4.10 < 4.14.49 | 4.14.49 |
| linux | linux_kernel | >= 4.15 < 4.16.15 | 4.16.15 |
| linux | linux_kernel | >= 4.5 < 4.9.108 | 4.9.108 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c
vendor_redhat·2019-11-22·CVSS 7.8
CVE-2019-18675 [HIGH] CWE-190 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c
kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
Package: kernel (Red Hat Enterprise Linux 5) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8
Debian
CVE-2019-18675: linux - The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia...
vendor_debian·2019·CVSS 7.8
CVE-2019-18675 [HIGH] CVE-2019-18675: linux - The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia...
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
Scope: local
bookworm: resolved (fixed in 4.16.16-1)
bullseye: resolved (fixed in 4.16.16-1)
forky: resolved (fixed in 4.16.16-1)
sid: resolved (fixed in 4.16.16-1)
trixie: resolved (fixed in 4.16.16-1)
GHSA
GHSA-7xj8-cwpp-wfwj: The Linux kernel through 5
ghsa_unreviewed·2022-05-24
CVE-2019-18675 [HIGH] CWE-190 GHSA-7xj8-cwpp-wfwj: The Linux kernel through 5
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
OSV
CVE-2019-18675: The Linux kernel through 5
osv·2019-11-25·CVSS 7.8
CVE-2019-18675 [HIGH] CVE-2019-18675: The Linux kernel through 5
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18675 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c
bugzilla·2019-11-27·CVSS 7.8
CVE-2019-18675 [HIGH] CVE-2019-18675 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c
CVE-2019-18675 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c
A vulnerability was found in Linux kernel has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
Reference:
https://deshal3v.github.io/blog/kernel-research/mmap_exploitation
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/media/usb/cpia2/cpia2_core.c
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1777478]
---
This was fixed upstream with commit be83bbf806822b1b8
Bugzilla
CVE-2019-18675 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c [fedora-all]
bugzilla·2019-11-27·CVSS 7.8
CVE-2019-18675 [HIGH] CVE-2019-18675 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c [fedora-all]
CVE-2019-18675 kernel: integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
https://deshal3v.github.io/blog/kernel-research/mmap_exploitationhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=be83bbf806822b1b89e0a0f23cd87cddc409e429https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/media/usb/cpia2/cpia2_core.chttps://security.netapp.com/advisory/ntap-20200103-0001/https://deshal3v.github.io/blog/kernel-research/mmap_exploitationhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=be83bbf806822b1b89e0a0f23cd87cddc409e429https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/media/usb/cpia2/cpia2_core.chttps://security.netapp.com/advisory/ntap-20200103-0001/
2019-11-25
Published