CVE-2019-11884
Vulnerability Summary
Timeline
Description
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
CVSS Metrics
- v4.0•MEDIUM•Score: 4.6CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- v3.1•LOW•Score: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.50%• Percentile: 42%
Affected Systems
- canonical•ubuntu_linux
16.04 | 18.04 | 19.04
- debian•linux
< 4.19.37-4 | < 4.19.37-4 | < 4.19.37-4 | < 4.19.37-4
- ubuntu•linux
all | < 4.4.0-157.185 | < 4.15.0-55.60
- ubuntu•linux-aws
< 4.4.0-1054.58 | < 4.4.0-1090.101 | < 4.15.0-1047.49
- ubuntu•linux-aws-fips
< 4.15.0-2018.18 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1047.49~16.04.1
- ubuntu•linux-azure
< 4.15.0-1059.64~14.04.1 | < 4.15.0-1051.56 | < 4.18.0-1025.27~18.04.1
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1015.20
- ubuntu•linux-gcp
< 4.15.0-1037.39~16.04.1 | < 4.15.0-1037.39
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1037.39
- ubuntu•linux-hwe
< 4.15.0-55.60~16.04.2 | < 5.0.0-23.24~18.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1052.59 | < 4.15.0-1039.39
- ubuntu•linux-lts-xenial
< 4.4.0-164.192~14.04.1
- ubuntu•linux-oem
< 4.15.0-1050.57
- ubuntu•linux-oem-osp1
< 5.0.0-1015.16
- ubuntu•linux-oracle
< 4.15.0-1018.20~16.04.1 | < 4.15.0-1018.20
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1117.126 | < 4.15.0-1041.44
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1121.127 | < 4.15.0-1058.64
- debian•debian_linux
8.0 | 9.0
- fedoraproject•fedora
28 | 29 | 30
- linux•linux_kernel
< 5.0.15
- opensuse•leap
15.0 | 15.1 | 42.3
- redhat•enterprise_linux
8.0
- redhat•enterprise_linux_eus
8.1 | 8.2 | 8.4 | 8.6
- redhat•enterprise_linux_for_real_time
8.0
- redhat•enterprise_linux_for_real_time_for_nfv_tus
8.2 | 8.4 | 8.6
- redhat•enterprise_linux_for_real_time_tus
8.2 | 8.4 | 8.6
- redhat•enterprise_linux_server_aus
8.2 | 8.4 | 8.6
- redhat•enterprise_linux_server_tus
8.2 | 8.4 | 8.6
References (33)
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.15
- https://github.com/torvalds/linux/commit/a1616a5ac99ede5d605047a9012481ce7ff18b16
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a1616a5ac99ede5d605047a9012481ce7ff18b16
- http://www.securityfocus.com/bid/108299
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LAYXGGJUUYPOMCBZGGDCUZFLUU3JOZG5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PF2PDXUGOFEOTPVEACKFIHQB6O4XUIZD/
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KPWHQHNM2MSGO3FDJVIQXQNKYVR7TV45/
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00071.html
- https://www.debian.org/security/2019/dsa-4465
- https://lists.debian.org/debian-lts-announce/2019/06/msg00010.html
- https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html
- https://seclists.org/bugtraq/2019/Jun/26
- https://usn.ubuntu.com/4068-1/
- https://usn.ubuntu.com/4068-2/
- https://usn.ubuntu.com/4069-1/
- https://usn.ubuntu.com/4076-1/
- https://usn.ubuntu.com/4069-2/
- https://usn.ubuntu.com/4118-1/
- https://access.redhat.com/errata/RHSA-2019:3309
- https://access.redhat.com/errata/RHSA-2019:3517
- https://access.redhat.com/errata/RHSA-2020:0740
- https://ubuntu.com/security/CVE-2019-11884
- https://git.kernel.org/linus/a1616a5ac99ede5d605047a9012481ce7ff18b16
- https://ubuntu.com/security/notices/USN-4068-1
- https://ubuntu.com/security/notices/USN-4068-2
- https://ubuntu.com/security/notices/USN-4069-1
- https://ubuntu.com/security/notices/USN-4076-1
- https://ubuntu.com/security/notices/USN-4069-2
- https://ubuntu.com/security/notices/USN-4118-1
- https://www.cve.org/CVERecord?id=CVE-2019-11884
- https://security-tracker.debian.org/tracker/CVE-2019-11884