Hide Forgot
A use-after-free flaw was found in dvb_usb_device_exit in drivers/media/usb/dvb-usb/dvb-usb-init.c in USB DVB media access. This flaw could allow an attacker to crash the system at device disconnect. This vulnerability could even lead to a kernel information leak problem. Reference: https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6cf97230cd5f36b7665099083272595c55d72be7 https://syzkaller.appspot.com/bug?id=a53c9c9dd2981bfdbfbcbc1ddbd35595eda8bced
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1743581]
This was fixed for Fedora with the 5.2.3 stable updates.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.