Out-of-bounds read in Linux kernel - CVE-2018-19985
Published: September 3, 2019 / Updated: September 3, 2019
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when the function "hso_get_config_data" in "drivers/net/usb/hso.c" reads "if_num" from the USB device (as a u8) and uses it to index a small array. An authenticated local user with physical access to the system can use a malicious USB, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Opensuse
IBM MQ Appliance
4769 Developer's Toolkit
kernel-rt (Red Hat package)
How to mitigate CVE-2018-19985
IBM MQ Appliance - update to 9.2.0.6
kernel-rt (Red Hat package) - update to 4.18.0-147.rt24.93.el8
4769 Developer's Toolkit - update to 7.3.44
External References
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.148
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.13
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.91
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.170
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20