4.6
CVSSv3

CVE-2019-19947

Published: 24/12/2019 Updated: 09/11/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.6 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In the Linux kernel up to and including 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 8.0

canonical ubuntu linux 18.04

canonical ubuntu linux 14.04

canonical ubuntu linux 19.10

canonical ubuntu linux 16.04

netapp cloud backup -

netapp steelstore cloud integrated storage -

netapp data availability services -

netapp solidfire & hci management node -

netapp active iq unified manager -

netapp solidfire baseboard management controller -

netapp fas/aff baseboard management controller -

netapp e-series santricity os controller

netapp hci baseboard management controller h610s

netapp aff baseboard management controller a700s

Mailing Lists

Hi, there some info-leaks vulnerabilities in Linux kernel USB drivers that can be triggered by an external malicious USB device Description: In the Linux kernel through 546, there are some information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leafc driver More details in cvemitre ...