CVE-2019-18683 Details
Description
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.18, < 4.4.204 >= 4.5, < 4.9.204 >= 4.10, < 4.14.157 >= 4.15, < 4.19.87 >= 4.20, < 5.3.14 >= 5.4, < 5.4.1 |
CPE
Remediation
| |
| canonical ubuntu linux | 14.04 16.04 18.04 19.10 |
CPE
Remediation
| |
| opensuse leap | 15.1 |
CPE
Remediation
| |
| netapp active iq unified manager | All versions |
CPE
Remediation
| |
| netapp cloud backup | All versions |
CPE
Remediation
| |
| netapp data availability services | All versions |
CPE
Remediation
| |
| netapp e-series santricity os controller | >= 11.0.0, <= 11.70.1 |
CPE
Remediation
| |
| netapp element software | All versions |
CPE
Remediation
| |
| netapp hci management node | All versions |
CPE
Remediation
| |
| netapp solidfire | All versions |
CPE
Remediation
| |
| netapp steelstore cloud integrated storage | All versions |
CPE
Remediation
| |
| broadcom fabric operating system | All versions |
CPE
Remediation
| |
| netapp a700s firmware | All versions |
CPE
Remediation
| |
| netapp a700s | All versions |
CPE
Remediation
| |
| netapp 8300 firmware | All versions |
CPE
Remediation
| |
| netapp 8300 | All versions |
CPE
Remediation
| |
| netapp 8700 firmware | All versions |
CPE
Remediation
| |
| netapp 8700 | All versions |
CPE
Remediation
| |
| netapp a400 firmware | All versions |
CPE
Remediation
| |
| netapp a400 | All versions |
CPE
Remediation
| |
| netapp h610s firmware | All versions |
CPE
Remediation
| |
| netapp h610s | All versions |
CPE
Remediation
| |
| debian debian linux | 8.0 |
CPE
Remediation
| |
Change History
21 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 7, 2024 | Reanalysis | [email protected] |
| Jun 6, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 18, 2022 | Modified Analysis | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Mar 2, 2020 | CVE Modified | [email protected] |
| Mar 2, 2020 | CVE Modified | [email protected] |
| Mar 2, 2020 | CVE Modified | [email protected] |
| Feb 25, 2020 | CVE Modified | [email protected] |
| Feb 5, 2020 | CVE Modified | [email protected] |
| Jan 31, 2020 | CVE Modified | [email protected] |
| Jan 29, 2020 | CVE Modified | [email protected] |
| Jan 9, 2020 | CVE Modified | [email protected] |
| Jan 9, 2020 | CVE Modified | [email protected] |
| Dec 12, 2019 | CVE Modified | [email protected] |
| Dec 5, 2019 | CVE Modified | [email protected] |
| Nov 8, 2019 | Initial Analysis | [email protected] |
| Nov 5, 2019 | CVE Modified | [email protected] |