CVE-2019-18683
Published: 04 November 2019
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
From the Ubuntu security team
It was discovered that a race condition existed in the Virtual Video Test Driver in the Linux kernel. An attacker with write access to /dev/video0 on a system with the vivid module loaded could possibly use this to gain administrative privileges.
CVSS 3 base score: 7.0
Status
Package | Release | Status |
---|---|---|
linux Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-26.30)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-9.12)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-88.88)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.4.0-173.203)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Ignored
(was needs-triage ESM criteria)
|
|
Patches: Introduced by 3f682ffcf957b556a7868decd5593d765ed3455d Fixed by 6dcd5d7a7a29c1e4b8016a06aed78cd650cd8c27 Introduced by 6de8653f410c5413a557eb48e2492a93f7af664b Fixed by 6dcd5d7a7a29c1e4b8016a06aed78cd650cd8c27 |
||
linux-aws Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-1009.9)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-1005.5)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1060.62)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.4.0-1101.112)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Released
(4.4.0-1061.65)
|
|
linux-aws-5.0 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.0.0-1024.27~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-aws-5.3 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(5.3.0-1016.17~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-aws-hwe Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.15.0-1060.62~16.04.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-azure Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-1010.10)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-1006.6)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.0.0-1029.31~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.15.0-1071.76)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Released
(4.15.0-1071.76~14.04.1)
|
|
linux-azure-4.15 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(4.15.0-1082.92)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-azure-5.3 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.3.0-1013.14~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-azure-edge Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Ignored
(was needs-triage now end-of-life)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gcp Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-1009.9)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-1005.5)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.0.0-1029.30~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.15.0-1055.59)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gcp-4.15 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(4.15.0-1071.81)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gcp-5.3 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.3.0-1012.13~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gcp-edge Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Ignored
(was needs-triage now end-of-life)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gke-4.15 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1052.55)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gke-5.0 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.0.0-1029.30~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-gke-5.3 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.3.0-1012.13~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-hwe Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.3.0-40.32~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.15.0-88.88~16.04.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Ignored
(was needed now end-of-life)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Ignored
(was needed now end-of-life)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-kvm Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-1009.9)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-1004.4)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1053.53)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.4.0-1065.72)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-lts-trusty Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Released
(4.4.0-173.203~14.04.1)
|
|
linux-oem Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1073.83)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Ignored
(was needs-triage now end-of-life)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-oem-5.6 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.6.0-1007.7)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.6.0-1007.7)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-oem-osp1 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.0.0-1037.42)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-oracle Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-1009.9)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-1005.5)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1033.36)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.15.0-1033.36~16.04.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-oracle-5.0 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.0.0-1010.15~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-oracle-5.3 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(5.3.0-1011.12~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-raspi Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-1008.8)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-1007.7)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-raspi2 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Ignored
(was needed now end-of-life)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1055.59)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.4.0-1128.137)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-raspi2-5.3 Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(5.3.0-1018.20~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-riscv Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(5.4.0-24.28)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(5.4.0-24.28)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
linux-snapdragon Launchpad, Ubuntu, Debian |
Upstream |
Released
(5.5~rc1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(4.15.0-1072.79)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.4.0-1132.140)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
Notes
Author | Note |
---|---|
tyhicks | This rarely used driver module cannot be loaded by an unprivileged user so the impact is lessened |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18683
- https://www.openwall.com/lists/oss-security/2019/11/02/1
- https://lore.kernel.org/lkml/20191103221719.27118-1-alex.popov@linux.com/
- https://usn.ubuntu.com/usn/usn-4254-1
- https://usn.ubuntu.com/usn/usn-4254-2
- https://usn.ubuntu.com/usn/usn-4258-1
- https://usn.ubuntu.com/usn/usn-4284-1
- https://usn.ubuntu.com/usn/usn-4287-1
- https://usn.ubuntu.com/usn/usn-4287-2
- NVD
- Launchpad
- Debian