VulnerabilityModified
CVE-2018-20169
An issue was discovered in the Linux kernel before 4.19.9.
MEDIUM 6.8EPSS 0.59%
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- linux/linux kernel · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=704620afc70cf47abb9d6a1a57f3825d2bca49cfMailing List, Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3309Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:3517Third Party Advisory, VDB Entry
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.9Mailing List, Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/704620afc70cf47abb9d6a1a57f3825d2bca49cfPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3879-1/Third Party Advisory
- https://usn.ubuntu.com/3879-2/Third Party Advisory
- https://usn.ubuntu.com/4094-1/Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/4118-1/Third Party Advisory, VDB Entry
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=704620afc70cf47abb9d6a1a57f3825d2bca49cfMailing List, Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3309Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:3517Third Party Advisory, VDB Entry
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.9Mailing List, Patch, Vendor Advisory
- https://github.com/torvalds/linux/commit/704620afc70cf47abb9d6a1a57f3825d2bca49cfPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3879-1/Third Party Advisory
- https://usn.ubuntu.com/3879-2/Third Party Advisory
- https://usn.ubuntu.com/4094-1/Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/4118-1/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.