First published: Mon Nov 04 2019(Updated: )
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=3.18<4.4.204 | |
Linux Kernel | >=4.5<4.9.204 | |
Linux Kernel | >=4.10<4.14.157 | |
Linux Kernel | >=4.15<4.19.87 | |
Linux Kernel | >=4.20<5.3.14 | |
Linux Kernel | >=5.4<5.4.1 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
openSUSE | =15.1 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp cloud backup | ||
netapp data availability services | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
NetApp Element Software | ||
netapp hci management node | ||
netapp solidfire | ||
NetApp SteelStore | ||
broadcom fabric operating system | ||
All of | ||
NetApp AFF A700s Firmware | ||
netapp a700s | ||
All of | ||
NetApp AFF 8300 Firmware | ||
NetApp FAS8300 | ||
All of | ||
NetApp AFF 8700 Firmware | ||
NetApp FAS8700 | ||
All of | ||
NetApp AFF A400 Firmware | ||
NetApp FAS A400 | ||
All of | ||
netapp h610s firmware | ||
netapp h610s | ||
Debian GNU/Linux | =8.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
Debian | =8.0 | |
Linux Kernel | <=5.3.8 | |
NetApp AFF A700s Firmware | ||
netapp a700s | ||
NetApp AFF 8300 Firmware | ||
NetApp FAS8300 | ||
NetApp AFF 8700 Firmware | ||
NetApp FAS8700 | ||
NetApp AFF A400 Firmware | ||
NetApp FAS A400 | ||
netapp h610s firmware | ||
netapp h610s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18683 has been assigned a severity rating that indicates a potential for privilege escalation under specific conditions.
To fix CVE-2019-18683, upgrade your Linux kernel to version 5.10.223-1 or later.
CVE-2019-18683 affects several Linux distributions where local users have access to /dev/video0 and the vivid driver is loaded.
CVE-2019-18683 is a privilege escalation vulnerability due to race conditions in the Linux kernel's vivid driver.
CVE-2019-18683 is exploitable only by local users, not remotely.