Vulnerability CVE-2019-3819: Information

Description

A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.

Severity: MEDIUM (4.4) Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Published: Jan. 25, 2019
Modified: Oct. 19, 2020
Error type identifier: CWE-835

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
kernel-image-std-debugsisyphus4.14.101-alt16.1.90-alt2ALT-PU-2019-1251-1221587Fixed
kernel-image-std-debugc9f24.14.101-alt14.19.102-alt1ALT-PU-2019-1251-1221587Fixed
kernel-image-std-defsisyphus4.14.102-alt16.1.90-alt2ALT-PU-2019-1285-1222380Fixed
kernel-image-std-defp104.14.102-alt15.10.216-alt1ALT-PU-2019-1285-1222380Fixed
kernel-image-std-defp94.14.102-alt15.4.275-alt1ALT-PU-2019-1285-1222380Fixed
kernel-image-std-defp84.9.160-alt0.M80P.14.9.337-alt0.M80P.1ALT-PU-2019-1317-1222834Fixed
kernel-image-std-defc9f24.14.102-alt15.10.214-alt0.c9f.2ALT-PU-2019-1285-1222380Fixed
kernel-image-std-defc74.4.183-alt0.M70C.14.4.277-alt0.M70C.1ALT-PU-2019-2175-1233233Fixed
kernel-image-std-paec9f24.14.101-alt14.19.72-alt1ALT-PU-2019-1252-1221589Fixed
kernel-image-tegrap94.9.140-alt24.9.140-alt2ALT-PU-2019-2234-1234165Fixed
kernel-image-tegrac9f24.9.140-alt24.9.140-alt2ALT-PU-2019-2234-1234165Fixed
kernel-image-un-defsisyphus4.19.24-alt16.6.30-alt2ALT-PU-2019-1286-1222382Fixed
kernel-image-un-defp104.19.24-alt16.1.85-alt1ALT-PU-2019-1286-1222382Fixed
kernel-image-un-defp94.19.24-alt15.10.216-alt2ALT-PU-2019-1286-1222382Fixed
kernel-image-un-defp84.19.27-alt0.M80P.14.19.310-alt0.M80P.1ALT-PU-2019-1431-1224040Fixed
kernel-image-un-defc10f14.19.24-alt16.1.85-alt0.c10f.1ALT-PU-2019-1286-1222382Fixed
kernel-image-un-defc9f24.19.24-alt15.10.29-alt2ALT-PU-2019-1286-1222382Fixed
kernel-image-un-defc74.9.277-alt0.M70C.14.9.277-alt0.M70C.1ALT-PU-2021-3032-1281292Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3819
  • Issue Tracking
  • Patch
  • Third Party Advisory
106730
  • Third Party Advisory
  • VDB Entry
[debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update
  • Mailing List
  • Third Party Advisory
USN-3932-2
  • Third Party Advisory
USN-3932-1
  • Third Party Advisory
openSUSE-SU-2019:1193
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20190503 [SECURITY] [DLA 1771-1] linux-4.9 security update
  • Mailing List
  • Third Party Advisory
USN-4115-1
  • Third Party Advisory
USN-4118-1
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      Start including
      4.18

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      Configuration 4

      cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*