UBUNTU-CVE-2019-11884
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11884
UBUNTU-CVE-2019-11884
Summary:
Details: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
References: https://ubuntu.com/security/CVE-2019-11884, https://git.kernel.org/linus/a1616a5ac99ede5d605047a9012481ce7ff18b16, https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.15, https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a1616a5ac99ede5d605047a9012481ce7ff18b16, https://ubuntu.com/security/notices/USN-4068-1, https://ubuntu.com/security/notices/USN-4068-2, https://ubuntu.com/security/notices/USN-4069-1, https://ubuntu.com/security/notices/USN-4076-1, https://ubuntu.com/security/notices/USN-4069-2, https://ubuntu.com/security/notices/USN-4118-1, https://www.cve.org/CVERecord?id=CVE-2019-11884
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
