ZeroHour

CVE-2019-11884

CVSS 3.1
3.3 low
EPSS
<1%p41
Published
()
Modified
Description

The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.

Vendors
linuxfedoraprojectdebiancanonicalredhatopensuse
Products
linux kernel, fedora, debian linux, ubuntu linux, enterprise linux, enterprise linux eus, enterprise linux for real time, enterprise linux for real time for nfv tus, enterprise linux for real time tus, enterprise linux server aus, enterprise linux server tus, leap
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.