Red Hat released kernel and kernel-rt updates for supported RHEL 7, RHEL 8, and associated Real Time, NFV, and extended-support variants, addressing CVE-2019-19527 alongside CVE-2020-10757, CVE-2020-12653, CVE-2020-12654, and, in selected updates, the PowerPC Spectre-RSB issue CVE-2019-18660. The RHEL 7 update provides kernel version 3.10.0-1127.18.2.el7; affected administrators must install the applicable packages and reboot for the patched kernel to load.
CVE-2019-19527 affects the Linux USB HID hiddev driver in drivers/hid/usbhid/hiddev.c. A malicious or improperly initialized USB device can trigger an error-path use-after-free condition, potentially causing memory corruption, a kernel panic, or privilege escalation; Red Hat rated it Moderate because exploitation requires physical access. Upstream commit 9c09b214f30e3c11f9b0b03f89442df03643794d corrects the issue by rechecking that the device remains connected after obtaining the existence lock and returning -ENODEV when it has been disconnected.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2020:3221 for RHEL Real Time 7 variants, providing kernel-rt version 3.10.0-1127.18.2.rt56.1116.el7. It remediated CVE-2019-19527 and three additional kernel vulnerabilities, with a reboot required to activate the update.
Red Hat issued Important advisory RHSA-2020:3220 for RHEL 7, releasing kernel version 3.10.0-1127.18.2.el7. The update fixed CVE-2019-19527 and CVE-2020-10757, CVE-2020-12653, and CVE-2020-12654; affected systems needed a reboot.
Fan Yang reported CVE-2020-10757 to Openwall oss-security. The Linux kernel flaw, present since v4.5, could cause page-table corruption when mremap moved a huge DAX-backed NVDIMM mapping into anonymous memory; a proposed patch added pmd_devmap() handling in mm/mremap.c.
Red Hat issued Moderate-security advisory RHSA-2020:1378 for RHEL 8 Real Time kernel packages, providing kernel-rt version 4.18.0-147.8.1.rt24.101.el8_1. The update remediated CVE-2019-19527 for affected Real Time, NFV, telecommunications, and Extended Life Cycle offerings; systems required a reboot.
Red Hat issued Moderate-security advisory RHSA-2020:1372 for RHEL 8, fixing CVE-2019-19527 alongside PowerPC vector-register disclosure flaws and the CVE-2019-18660 incomplete Spectre-RSB mitigation. Systems required a reboot after installing the updated kernel.
Debian issued DLA-2114-1, updating linux-4.9 to address CVE-2019-19527.
Red Hat issued Important advisory RHSA-2020:0592 for specified RHEL 7.4 AUS, TUS, and SAP update-service offerings. Kernel version 3.10.0-693.64.1.el7 fixed CVE-2018-20976, CVE-2019-11085, CVE-2019-14895, and CVE-2019-17133; affected systems required a reboot.
Debian issued DLA-2068-1, a Linux security update addressing CVE-2019-19527.
CVE-2019-19527 was published for a Linux kernel USB HID hiddev use-after-free vulnerability that a malicious USB device could trigger. An Openwall oss-security advisory covering this and other Linux USB issues was also published that day.
Linux kernel commit 9c09b214f30e3c11f9b0b03f89442df03643794d was committed to prevent hiddev from opening a USB HID device that was concurrently disconnected, fixing a Syzbot-reported use-after-free condition in drivers/hid/usbhid/hiddev.c.
CVE-2019-11085 was identified in Linux Intel i915 GVT KVM graphics-device passthrough code. A guest using explicitly configured i915 passthrough could crash its host or potentially escalate privileges; upstream commit 51b00d8509dc69c98740da2ad07308b630d3eb7d and Fedora's Linux 5.0 stable rebase addressed the issue, while Red Hat issued affected-product advisories.
Red Hat addressed CVE-2019-15031 in Red Hat Enterprise Linux 7 through RHSA-2020:1493. The PowerPC flaw could allow a local attacker using transactional-memory instructions to nondeterministically obtain vector-register values from another local process.
Red Hat addressed the PowerPC vector-register information-disclosure vulnerability CVE-2019-15030 in Red Hat Enterprise Linux 7 through RHSA-2020:0740. The flaw could allow a local user to obtain vector-register values from another local process during PowerPC FPU task switching.
Red Hat issued RHSA-2020:4236 to remediate CVE-2019-19527 in the Red Hat Enterprise Linux 7.7 Extended Update Support kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.