CVE-2019-18675

HIGH

Linux kernel <5.3.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.

Scores

CVSS v3 7.8
EPSS 0.0053
EPSS Percentile 40.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
linux/linux_kernel < 3.16.60
Published Nov 25, 2019
Tracked Since Feb 18, 2026