Wind River Support Network

HomeDefectsSCP7-952
Fixed

SCP7-952 : Security Advisory - linux - CVE-2018-19824

Created: Dec 19, 2018    Updated: Sep 17, 2019
Resolved Date: Sep 17, 2019
Found In Version: 7.0.0.30
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Kernel

Description

In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.

https://nvd.nist.gov/vuln/detail/CVE-2018-19824
Live chat
Online