CVE-2019-2029
published 2019-04-19CVE-2019-2029: In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.71%
50.0th percentile
In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-120612744.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | android | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6hg-g687-vqrf: In btm_proc_smp_cback of tm_ble
ghsa_unreviewed·2022-05-24
CVE-2019-2029 [HIGH] CWE-416 GHSA-f6hg-g687-vqrf: In btm_proc_smp_cback of tm_ble
In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-120612744.
Android
CVE-2019-2029: Android Security Bulletin 2019-04-01
CVE: CVE-2019-2029
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7
vendor_android·2019-04-01·CVSS 8.8
CVE-2019-2029 [HIGH] CVE-2019-2029: Android Security Bulletin 2019-04-01
CVE: CVE-2019-2029
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7
Android Security Bulletin 2019-04-01
CVE: CVE-2019-2029
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-120612744
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-9517 kernel: l2tp: Race condition between pppol2tp_session_create() and l2tp_eth_create()
bugzilla·2018-09-19·CVSS 6.7
CVE-2018-9517 [MEDIUM] CVE-2018-9517 kernel: l2tp: Race condition between pppol2tp_session_create() and l2tp_eth_create()
CVE-2018-9517 kernel: l2tp: Race condition between pppol2tp_session_create() and l2tp_eth_create()
A race condition between pppol2tp_session_create() and l2tp_eth_create() in net/l2tp/l2tp_netlink.c in the Linux kernel. Calling l2tp_tunnel_find() may result in a new tunnel being created with tunnel id of a previous removed tunnel which wouldn't be protected by the reference counter.
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f026bc29a8e093edfbb2a77700454b285c97e8ad
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1631046]
---
This was fixed for Fedora with the 4.14 rebases.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2029 https://acces
Bugzilla
CVE-2018-16658 kernel: Information leak in cdrom_ioctl_drive_status
bugzilla·2018-09-11·CVSS 6.1
CVE-2018-16658 [MEDIUM] CVE-2018-16658 kernel: Information leak in cdrom_ioctl_drive_status
CVE-2018-16658 kernel: Information leak in cdrom_ioctl_drive_status
An information leak was discovered in the Linux kernel in cdrom_ioctl_drive_status() function in drivers/cdrom/cdrom.c that could be used by local attackers to read kernel memory at certain location.
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8f3fafc9c2f0ece10832c25f7ffcb07c97a32ad4
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1628143]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2029 https://access.redhat.com/errata/RHSA-2019:2029
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2043 https://access.redhat.com/e
2019-04-19
Published