CVE-2019-18683
Last modified
CVE-2019-18683 is a high-severity vulnerability rated 7/10 on the CVSS scale. An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.18, < 4.4.204 |
| Linux | Linux Kernel | >= 4.5, < 4.9.204 |
| Linux | Linux Kernel | >= 4.10, < 4.14.157 |
| Linux | Linux Kernel | >= 4.15, < 4.19.87 |
| Linux | Linux Kernel | >= 4.20, < 5.3.14 |
| Linux | Linux Kernel | >= 5.4, < 5.4.1 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.10 |
| Opensuse | Leap | 15.1 |
| Netapp | Active Iq Unified Manager | All versions |
| Netapp | Cloud Backup | All versions |
| Netapp | Data Availability Services | All versions |
| Netapp | E-Series Santricity Os Controller | >= 11.0.0, <= 11.70.1 |
| Netapp | Element Software | All versions |
| Netapp | Hci Management Node | All versions |
| Netapp | Solidfire | All versions |
| Netapp | Steelstore Cloud Integrated Storage | All versions |
| Broadcom | Fabric Operating System | All versions |
| Netapp | A700s Firmware | All versions |
| Netapp | 8300 Firmware | All versions |
| Netapp | 8700 Firmware | All versions |
| Netapp | A400 Firmware | All versions |
| Netapp | H610s Firmware | All versions |
| Debian | Debian Linux | 8.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155890/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/11/05/1Exploit, Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/10Mailing List, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191205-0001/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4258-1/Third Party Advisory
- https://usn.ubuntu.com/4284-1/Third Party Advisory
- https://usn.ubuntu.com/4287-1/Third Party Advisory
- https://usn.ubuntu.com/4287-2/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/11/02/1Exploit, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/155890/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/11/05/1Exploit, Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/10Mailing List, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191205-0001/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4258-1/Third Party Advisory
- https://usn.ubuntu.com/4284-1/Third Party Advisory
- https://usn.ubuntu.com/4287-1/Third Party Advisory
- https://usn.ubuntu.com/4287-2/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/11/02/1Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-18683?
How severe is CVE-2019-18683?
How do I fix CVE-2019-18683?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-18676An issue was discovered in Squid 3.x and 4.x through 4.8. Du…7.5
- CVE-2019-18677An issue was discovered in Squid 3.x and 4.x through 4.8 whe…6.1
- CVE-2019-18678An issue was discovered in Squid 3.x and 4.x through 4.8. It…5.3
- CVE-2019-18679An issue was discovered in Squid 2.x, 3.x, and 4.x through 4…7.5
- CVE-2019-1868A vulnerability in the web-based management interface of Cis…7.5
- CVE-2019-18680An issue was discovered in the Linux kernel 4.4.x before 4.4…7.5
- CVE-2019-18684Sudo through 1.8.29 allows local users to escalate to root i…7
- CVE-2019-18685Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-18686Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-18687Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-18688Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-18689Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2019-18683?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
