CVE-2019-19537
published 2019-12-03CVE-2019-19537: In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka…
PriorityP413medium4.2CVSS 3.1
AVPACHPRNUINSUCNINAH
EPSS
0.28%
20.5th percentile
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.2.17-1 (bookworm) | linux 5.2.17-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 5.2.10 | 5.2.10 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.2MEDIUM
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2019-19537: USB
vendor_android·2020-03-01·CVSS 4.2
CVE-2019-19537 [MEDIUM] CVE-2019-19537: USB
Android Security Bulletin 2020-03-01
CVE: CVE-2019-19537
Severity: HIGH
Type: EoP
Component: USB
References: A-146258055
Upstream kernel
Red Hat
kernel: race condition caused by a malicious USB device in the USB character device driver layer
vendor_redhat·2019-08-12·CVSS 4.2
CVE-2019-19537 [MEDIUM] CWE-362 kernel: race condition caused by a malicious USB device in the USB character device driver layer
kernel: race condition caused by a malicious USB device in the USB character device driver layer
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.
A flaw was found in the Linux kernel, where there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer. An attacker who can hotplug at least two devices of this class can cause a use-after-free situation.
Mitigation: Many Character devices can trigger this flaw as they leverage the lower levels of the USB subsystem.
The safest method that I have found would be to disable USB ports that are able to be attacked
using this method,
Debian
CVE-2019-19537: linux - In the Linux kernel before 5.2.10, there is a race condition bug that can be cau...
vendor_debian·2019·CVSS 4.2
CVE-2019-19537 [MEDIUM] CVE-2019-19537: linux - In the Linux kernel before 5.2.10, there is a race condition bug that can be cau...
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.
Scope: local
bookworm: resolved (fixed in 5.2.17-1)
bullseye: resolved (fixed in 5.2.17-1)
forky: resolved (fixed in 5.2.17-1)
sid: resolved (fixed in 5.2.17-1)
trixie: resolved (fixed in 5.2.17-1)
GHSA
GHSA-hp8p-42mw-fvq9: In the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2019-19537 [MEDIUM] GHSA-hp8p-42mw-fvq9: In the Linux kernel before 5
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.
OSV
CVE-2019-19537: In the Linux kernel before 5
osv·2019-12-03·CVSS 4.2
CVE-2019-19537 [MEDIUM] CVE-2019-19537: In the Linux kernel before 5
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19537 kernel: race condition caused by a malicious USB device in the USB character device driver layer [fedora-all]
bugzilla·2019-12-13·CVSS 4.2
CVE-2019-19537 [MEDIUM] CVE-2019-19537 kernel: race condition caused by a malicious USB device in the USB character device driver layer [fedora-all]
CVE-2019-19537 kernel: race condition caused by a malicious USB device in the USB character device driver layer [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2019-19537 kernel: race condition caused by a malicious USB device in the USB character device driver layer
bugzilla·2019-12-13·CVSS 4.2
CVE-2019-19537 [MEDIUM] CVE-2019-19537 kernel: race condition caused by a malicious USB device in the USB character device driver layer
CVE-2019-19537 kernel: race condition caused by a malicious USB device in the USB character device driver layer
A flaw was found in the Linux kernel where there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer. An attacker who is able to hot plug at least two devices of this class can cause a a use-after-free situation.
This affects the generic character device layer devices and not a specific device driver.
References:
http://www.openwall.com/lists/oss-security/2019/12/03/4
http://seclists.org/oss-sec/2019/q4/115
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.10
Upstream Patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=303911cfc5b95d33687d9046133ff184cf5043ff
Discussion:
Cr
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.htmlhttp://www.openwall.com/lists/oss-security/2019/12/03/4https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.10https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=303911cfc5b95d33687d9046133ff184cf5043ffhttps://lists.debian.org/debian-lts-announce/2020/01/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.htmlhttp://www.openwall.com/lists/oss-security/2019/12/03/4https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.10https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=303911cfc5b95d33687d9046133ff184cf5043ffhttps://lists.debian.org/debian-lts-announce/2020/01/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
2019-12-03
Published