In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver, aka CID-9c09b214f30e.
| Software | From | Fixed in |
|---|---|---|
| debian / debian_linux | 8.0 | 8.0.x |
| opensuse / leap | 15.1 | 15.1.x |
| linux / linux_kernel | 4.20 | 5.2.10 |
| linux / linux_kernel | 4.15 | 4.19.68 |
| linux / linux_kernel | 4.10 | 4.14.140 |
| linux / linux_kernel | 4.5 | 4.9.190 |
| linux / linux_kernel | 3.17 | 4.4.190 |
| linux / linux_kernel | 2.6.30 | 3.16.79 |