Andrei Konovalov from Google 15 vulnerabilities in USB drivers offered in the Linux kernel. This is the second batch of issues found during fuzz testing — this particular researcher identified them in 2017. There are still 14 vulnerabilities in the USB stack. The issues could potentially be exploited when connecting specially prepared USB devices to a computer. An attack is possible with physical access to the hardware and can lead to at least a kernel crash, but other manifestations are not excluded (for example, for a similar vulnerability identified in 2016. In the USB driver snd-usbmidi, it was possible to to execute code at the kernel level).
Out of the 15 issues, 13 have already been fixed in the current updates of the Linux kernel, but two vulnerabilities (CVE-2019-15290, CVE-2019-15291) remain unpatched in the latest release 5.2.9. The unpatched vulnerabilities can lead to NULL pointer dereference in the ath6kl and b2c2 drivers when receiving incorrect data from the device. Other vulnerabilities include:
- Use-after-free access to already freed memory areas in the v4l2-dev/radio-raremono, dvb-usb, sound/core, cpia2, and p54usb drivers;
- Double-free in the rio500 driver;
- NULL pointer dereference in the yurex, zr364xx, siano/smsusb, sisusbvga, line6/pcm, motu_microbookii, and line6 drivers.
Allikas: opennet.ru
