ZeroHour

CVE-2018-19985

CVSS 3.0
4.6 medium
EPSS
<1%p59
Published
()
Modified
Description

The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.

Vendors
linuxdebiannetapp
Products
linux kernel, debian linux, active iq performance analytics services, element software management node
Weakness
CWE-125
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.