The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.
2019-03-21T16:00:33.373
2024-11-21T03:58:56.517
Modified
CVSSv3.0: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 4.19.8 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Application | netapp | active_iq_performance_analytics_services | - | Yes |
Application | netapp | element_software_management_node | - | Yes |