LOW · 3.3

CVE-2019-11884

The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNAD...

Vulnerability Description

The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.

CVSS Score

3.3

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 5.0.15
FedoraprojectFedora28
DebianDebian Linux8.0
CanonicalUbuntu Linux16.04
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.1
RedhatEnterprise Linux For Real Time8.0
RedhatEnterprise Linux For Real Time For Nfv Tus8.2
RedhatEnterprise Linux For Real Time Tus8.2
RedhatEnterprise Linux Server Aus8.2
RedhatEnterprise Linux Server Tus8.2
OpensuseLeap15.0

References

FAQ

What is CVE-2019-11884?

CVE-2019-11884 is a vulnerability with a CVSS score of 3.3 (LOW). The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNAD...

How severe is CVE-2019-11884?

CVE-2019-11884 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11884?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Debian Debian Linux, Canonical Ubuntu Linux, Redhat Enterprise Linux.