Out-of-bounds read in Linux kernel - CVE-2018-19985

 

Out-of-bounds read in Linux kernel - CVE-2018-19985

Published: September 3, 2019 / Updated: September 3, 2019


Vulnerability identifier: #VU20806
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19985
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when the function "hso_get_config_data" in "drivers/net/usb/hso.c" reads "if_num" from the USB device (as a u8) and uses it to index a small array. An authenticated local user with physical access to the system can use a malicious USB, trigger out-of-bounds read error and read contents of memory on the system.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Opensuse
IBM MQ Appliance
4769 Developer's Toolkit
kernel-rt (Red Hat package)

How to mitigate CVE-2018-19985

Install updates from vendor's website.

Linux kernel - addressed in versions 4.4.170, 4.9.148, 4.14.91, 4.19.13, 4.20
IBM MQ Appliance - update to 9.2.0.6
kernel-rt (Red Hat package) - update to 4.18.0-147.rt24.93.el8
4769 Developer's Toolkit - update to 7.3.44

External References

Related Security Bulletins