MEDIUM
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation
Published Jun 7, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.43%
Description
In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
Affected products
-
Affected
- Android kernel
Configuration 2
- 8.0
Configuration 3
OR
- 16.04
- 18.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11743 Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00022.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://source.android.com/security/bulletin/2019-06-01 x_refsource_CONFIRMVendor Advisory
- https://usn.ubuntu.com/4094-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4118-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11743 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/07/msg00022.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://source.android.com/security/bulletin/2019-06-01 | x_refsource_CONFIRMVendor Advisory | |
| https://usn.ubuntu.com/4094-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/4118-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jun 7, 2019
Updated Aug 4, 2024
Reserved Dec 10, 2018
Link CVE-2019-2101
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data