| Revision Date: | 2019-08-07 | Version: | 1 | | Title: | CVE-2018-20961 on Ubuntu 19.04 (disco) - medium. | | Description: | In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact. It was discovered that the USB gadget Midi driver in the Linux kernel contained a double-free vulnerability when handling certain error conditions. A local attacker could use this to cause a denial of service (system crash).
| | Family: | unix | Class: | vulnerability | | Status: | | Reference(s): | CVE-2018-20961
| | Platform(s): | Ubuntu 19.04
| Product(s): | | | Definition Synopsis | | Ubuntu 19.04 (disco) is installed. AND Package Information
linux package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-10.11').
OR linux-gcp package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-1002.3').
OR linux-meta package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-10.11').
OR linux-meta-gcp package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-1002.3').
OR linux-meta-oem package in disco, is related to the CVE in some way and has been fixed (note: '4.15.0-1021.24').
OR linux-meta-oracle package in disco, is related to the CVE in some way and has been fixed (note: '4.15.0-1007.9').
OR linux-meta-raspi2 package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-1005.7').
OR linux-oem package in disco, is related to the CVE in some way and has been fixed (note: '4.15.0-1021.24').
OR linux-oracle package in disco, is related to the CVE in some way and has been fixed (note: '4.15.0-1007.9').
OR linux-raspi2 package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-1005.7').
OR linux-signed package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-10.11').
OR linux-signed-gcp package in disco, is related to the CVE in some way and has been fixed (note: '4.18.0-1002.3').
OR linux-signed-oem package in disco, is related to the CVE in some way and has been fixed (note: '4.15.0-1021.24').
OR linux-signed-oracle package in disco, is related to the CVE in some way and has been fixed (note: '4.15.0-1007.9').
OR linux-snapdragon package in disco, is related to the CVE in some way and has been fixed (note: '5.0.0-1010.10').
|
|