CVE-2019-19533 is an information-disclosure vulnerability in the Linux kernel's ttusb-dec USB media driver. A malicious USB device could trigger ttusb_dec_send_command() to transmit uninitialized kernel memory because the driver allocated its command buffer with kmalloc() and did not initialize every byte before passing it to usb_bulk_msg().
The affected code is in drivers/media/usb/ttusb-dec/ttusb_dec.c and impacts Linux kernels before version 5.3.4. Upstream commit a10feaf8c464 remediates the issue by replacing kmalloc() with zero-initializing kzalloc(), preventing residual kernel-memory contents from being sent to the connected USB device.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2019-19533 was published for an information-disclosure vulnerability in the Linux ttusb-dec USB media driver affecting kernel versions before 5.3.4. A malicious USB device could trigger disclosure of residual kernel memory.
Tomas Bortoli authored a patch replacing kmalloc() with zero-initializing kzalloc() in ttusb_dec_send_command(), preventing uninitialized kernel memory from being sent to a USB device. The issue had been reported by syzbot.
Mauro Carvalho Chehab committed the fix as a10feaf8c464c3f9cfdd3a8a7ce17e1c0d498da1, addressing uninitialized command-buffer bytes in the TTUSB-DEC media driver.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.