CVE-2018-19824
CVSS v3.0
7.8 (High)
CVSS v2.0
4.6 (Medium)
EPSS
0.04 % (11th)
Affected Products
3
Advisories
68
In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.
Weaknesses
- CWE-416
- Use After Free
- CVE Status
- PUBLISHED
- CNA
- MITRE
- Published Date
-
2018-12-03 17:29:00
(5 years ago) - Updated Date
-
2019-09-10 22:15:10
(5 years ago)
Affected Products
Loading...
Loading...
Configuration #1
|
Configuration #2
|
Configuration #3
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...