CVE-2019-3819Infinite Loop in Linux

CWE-835Infinite Loop21 documents9 sources
Severity
4.4MEDIUMNVD
OSV7.0OSV4.6OSV3.3
EPSS
0.0%
top 93.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 25
Latest updateMay 13

Description

A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages10 packages

CVEListV5the_linux_foundation/kernelfrom v4.18 and newer
Debianlinux/linux_kernel< 4.19.20-1+3
Ubuntulinux/linux_kernel< 4.4.0-145.171+2

Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 16.04, 18.04

Patches

🔴Vulnerability Details

9
GHSA
GHSA-794c-rcrg-7j7w: A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug2022-05-13
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression2019-09-11
OSV
linux, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 vulnerabilities2019-09-02
OSV
linux-aws vulnerabilities2019-09-02
OSV
linux-lts-xenial, linux-aws vulnerabilities2019-04-02

📋Vendor Advisories

8
Ubuntu
Linux kernel regression2019-09-11
Ubuntu
Linux kernel (AWS) vulnerabilities2019-09-02
Ubuntu
Linux kernel vulnerabilities2019-09-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities2019-04-02

💬Community

3
Bugzilla
CVE-2019-3819 kernel: infinite loop in drivers/hid/hid-debug.c:hid_debug_events_read() [fedora-all]2019-01-25
Bugzilla
CVE-2019-3819 kernel: infinite loop in drivers/hid/hid-debug.c:hid_debug_events_read()2019-01-24
Bugzilla
CVE-2018-9516 kernel: HID: debug: Buffer overflow in hid_debug_events_read() in drivers/hid/hid-debug.c2018-09-19