A vulnerability was found in hiddev_open in drivers/hid/usbhid/hiddev.c in USB human interface device class subsystem, in this problem if a USB device fails to initialize correctly list management code in the error handling path can delete a list entry while other USB code paths could be using it. This may lead to a use-after-free situation which is frequently used by attackers to corrupt memory, panic the system or possibly escalate privileges. Upstream Patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6d4472d7bec39917b54e4e80245784ea5d60ce49 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9c09b214f30e3c11f9b0b03f89442df03643794d References: https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.10 http://www.openwall.com/lists/oss-security/2019/12/03/4 http://seclists.org/oss-sec/2019/q4/115
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1783503]
This is fixed for Fedora with the 5.2.10 stable kernel update.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Statement: This issue is rated as Moderate because of the need of physical access to the system.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1378 https://access.redhat.com/errata/RHSA-2020:1378
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-19527
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1372 https://access.redhat.com/errata/RHSA-2020:1372
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:3220 https://access.redhat.com/errata/RHSA-2020:3220
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:3221 https://access.redhat.com/errata/RHSA-2020:3221
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.7 Extended Update Support Via RHSA-2020:4236 https://access.redhat.com/errata/RHSA-2020:4236