A use-after-free vulnerability, tracked as CVE-2019-19530, affected the Linux kernel's USB CDC-ACM driver in drivers/usb/class/cdc-acm.c. A malicious USB device could trigger the flaw on Linux kernel versions before 5.2.10, potentially compromising the affected system through unsafe handling of the USB control-interface object's lifetime.
The upstream fix, commit c52873e5a1ef72f845526d9f6a50704433f9c625, acquires the USB control-interface reference before CDC-ACM minor-number allocation and removes a later duplicate reference acquisition. The driver's destructor releases the retained reference, correcting cleanup behavior during failed allocation and normal device registration; Debian and openSUSE also issued advisories for affected packages.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Debian published DLA 2114-1, a linux-4.9 security update advisory referencing CVE-2019-19530.
Debian published DLA 2068-1, a Linux security update advisory addressing the issue tracked as CVE-2019-19530.
MITRE published CVE-2019-19530 for a use-after-free vulnerability in the Linux kernel USB CDC-ACM driver, affecting versions before 5.2.10 and triggerable by a malicious USB device.
openSUSE published security advisory openSUSE-SU-2019:2675 referencing CVE-2019-19530 and updates for the Linux kernel issue.
Linux commit c52873e5a1ef72f845526d9f6a50704433f9c625 changed drivers/usb/class/cdc-acm.c to acquire the control-interface reference before minor-number allocation, addressing the use-after-free condition. The correction was included in Linux kernel 5.2.10.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.