First published: Tue Dec 03 2019(Updated: )
In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <5.2.9 | |
Debian | =8.0 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19531 has been classified with medium severity due to its potential exploitation via malicious USB devices.
To fix CVE-2019-19531, you should upgrade the Linux kernel to version 5.2.9 or later.
CVE-2019-19531 affects Linux kernel versions prior to 5.2.9, as well as specific versions of Debian and openSUSE.
CVE-2019-19531 is a use-after-free vulnerability found in the drivers for USB devices.
CVE-2019-19531 can be exploited by connecting a malicious USB device to the system.