Description
The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1731-1 | linux security update |
Debian DLA |
DLA-1731-2 | linux regression update |
Debian DLA |
DLA-1771-1 | linux-4.9 security update |
EUVD |
EUVD-2018-11652 | The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space. |
Ubuntu USN |
USN-3910-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3910-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-4115-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4118-1 | Linux kernel (AWS) vulnerabilities |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:51:17.876Z
Reserved: 2018-12-09T00:00:00.000Z
Link: CVE-2018-19985
No data.
Status : Modified
Published: 2019-03-21T16:00:33.373
Modified: 2024-11-21T03:58:56.517
Link: CVE-2018-19985
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN