summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2019-12-03 22:30:11 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2019-12-03 22:30:11 +0100
commit7ccaada6bc11aadfe6069208c2ce123bf1e7366f (patch)
tree93f07ecb01a354c0d342356e8356fff1eaf0194c
parentd62f39fe256b6ee9929e0d6c59493a775053b771 (diff)
Add CVE-2019-19528
-rw-r--r--active/CVE-2019-1952816
1 files changed, 16 insertions, 0 deletions
diff --git a/active/CVE-2019-19528 b/active/CVE-2019-19528
new file mode 100644
index 000000000..5902cf7ad
--- /dev/null
+++ b/active/CVE-2019-19528
@@ -0,0 +1,16 @@
+Description: USB: iowarrior: fix use-after-free on disconnect
+References:
+ http://www.openwall.com/lists/oss-security/2019/12/03/4
+Notes:
+ carnil> The fix c468a8aa790e ("usb: iowarrior: fix deadlock on
+ carnil> disconnect") in 5.3-rc4 (and backported to 5.2.9, 4.19.67 and
+ carnil> 4.9.190) introduced the issue.
+Bugs:
+upstream: released (5.4-rc3) [edc4746f253d907d048de680a621e121517f484b]
+4.19-upstream-stable: released (4.19.80) [2fdcf7e19bdefc683da824264c0898af39bf8d50]
+4.9-upstream-stable: released (4.9.197) [323f425a7618fdb0b961dec2c58685fa32eafa1b]
+3.16-upstream-stable:
+sid: released (5.3.7-1)
+4.19-buster-security: needed
+4.9-stretch-security: N/A "Vulnerable code not yet present in released version"
+3.16-jessie-security:

© 2014-2024 Faster IT GmbH | imprint | privacy policy