CVE-2019-19525

Updated: 2023-12-06

CWE: Use After Free

Description:

In the Linux kernel before 5.3.6, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/ieee802154/atusb.c driver, aka CID-7fd25e6fc035.

CVSS3: 4.6


Vendor State

OS Vendor version Errata
Ubuntu 18.04 4.15.0-72.81 USN-4210-1
Ubuntu 18.04 AWS 4.15.0-1056.58 USN-4210-1
Ubuntu 16.04 HWE 4.15.0-72.81~16.04.1 USN-4210-1
Ubuntu 16.04 AWS HWE 4.15.0-1056.58~16.04.1 USN-4210-1
Ubuntu 16.04 GCP 4.15.0-1050.53 USN-4210-1
Ubuntu 16.04 HWE ESM 4.15.0-72.81~16.04.1 USN-4210-1
Ubuntu 16.04 GCP ESM 4.15.0-1050.53 USN-4210-1
Ubuntu 16.04 AWS HWE ESM 4.15.0-1056.58~16.04.1 USN-4210-1

KernelCare State

OS Original kernel version State
Ubuntu 18.04
Ready For Release
Ubuntu 18.04 AWS
Ready For Release
Ubuntu 16.04 HWE
Ready For Release
Ubuntu 16.04 AWS HWE
Ready For Release
Debian 9
4.9.110-3+deb9u4 show all hide all
4.9.110-3 4.9.130-2 4.9.144-2 4.9.144-3.1 4.9.144-3 4.9.189-3 4.9.30-2+deb9u2 4.9.30-2 4.9.65-3+deb9u2 4.9.65-3 4.9.80-2 4.9.82-1+deb9u3 4.9.82-1+deb9u2 4.9.168-1+deb9u2 4.9.189-3+deb9u1 4.9.110-3+deb9u3 4.9.107-1 4.9.30-2+deb9u1 4.9.168-1+deb9u5 4.9.168-1+deb9u4 4.9.110-3+deb9u2 4.9.168-1+deb9u3 4.9.88-1 4.9.110-3+deb9u1 4.9.88-1+deb9u1 4.9.51-1 4.9.110-1 4.9.30-2+deb9u5 4.9.65-1 4.9.80-1 4.9.30-2+deb9u4 4.9.189-3+deb9u2 4.9.65-3+deb9u1 4.9.130-1 4.9.30-2+deb9u3 4.9.110-2 4.9.168-1 4.9.135-1 4.9.110-3+deb9u6 4.9.110-3+deb9u5
Released
Debian 8 backports
4.9.189-3~deb8u1 show all hide all
4.9.144-3.1~deb8u1 4.9.110-1~deb8u1 4.9.110-3+deb9u4~deb8u1 4.9.110-3+deb9u1~deb8u1 4.9.110-3+deb9u5~deb8u1 4.9.168-1+deb9u3~deb8u1 4.9.168-1+deb9u4~deb8u1 4.9.168-1+deb9u5~deb8u1 4.9.189-3+deb9u1~deb8u1 4.9.189-3+deb9u2~deb8u1 4.9.30-2+deb9u2~bpo8+1 4.9.30-2+deb9u5~bpo8+1 4.9.30-2~bpo8+1 4.9.51-1~bpo8+1 4.9.65-3+deb9u1~bpo8+1 4.9.65-3+deb9u2~bpo8+1 4.9.65-3~bpo8+1 4.9.82-1+deb9u3~bpo8+1 4.9.88-1+deb9u1~bpo8+1 4.9.88-1~bpo8+1 4.9.110-3+deb9u2~deb8u1
Released
Ubuntu 16.04 GCP
Will Not Fix
Debian 10
4.19.67-2+deb10u1 show all hide all
4.19.37-5 4.19.37-5+deb10u2 4.19.67-2+deb10u2 4.19.67-2 4.19.37-5+deb10u1
Released
Endurance 7 eig 4.14
4.14.146-225.ELK.el6 show all hide all
4.14.146-225.ELK.el7
Released
Proofpoint
Ready For Release
Debian 10 cloud
4.19.67-2+deb10u2 show all hide all
4.19.28-2_bpo9+1
Released
Debian 9 backports
4.19.67-2+deb10u2~bpo9+1
Released
Ubuntu 16.04 HWE ESM
Will Not Fix
Ubuntu 16.04 GCP ESM
Will Not Fix
Ubuntu 16.04 AWS HWE ESM
Will Not Fix