Information disclosure in Linux kernel - CVE-2019-11884
Published: September 3, 2019
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability in the "do_hidp_sock_ioctl" function in "net/bluetooth/hidp/sock.c" exists due to the Bluetooth Human Interface Device Protocol (HIDP) implementation did not properly verify strings were NULL terminated in certain situations. A local authenticated user can gain unauthorized access to sensitive information from kernel stack memory via a "HIDPCONNADD" command, because a name field may not end with a '' character.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Fedora
kernel-alt (Red Hat package)
kernel-rt (Red Hat package)
kernel
kernel-headers
How to mitigate CVE-2019-11884
kernel-alt (Red Hat package) - update to 4.14.0-115.18.1.el7a
kernel-rt (Red Hat package) - update to 4.18.0-147.rt24.93.el8
kernel - addressed in versions 5.0.16-100.fc28, 5.0.16-200.fc29, 5.0.16-300.fc30
kernel-headers - addressed in versions 5.0.16-100.fc28, 5.0.16-200.fc29, 5.0.16-300.fc30
External References
- http://www.securityfocus.com/bid/108299
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.15
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a1616a5ac99ede5d605047a9012481ce7ff18b16
- https://github.com/torvalds/linux/commit/a1616a5ac99ede5d605047a9012481ce7ff18b16
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KPWHQHNM2MSGO3FDJVIQXQNKYVR7TV45/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LAYXGGJUUYPOMCBZGGDCUZFLUU3JOZG5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PF2PDXUGOFEOTPVEACKFIHQB6O4XUIZD/