CVE-2019-18683 is a privilege escalation vulnerability in the Linux kernel's Vivid driver (part of the V4L2 subsystem), affecting versions through 5.3.8. The vulnerability arises from multiple race conditions due to improper mutex locking in the functions vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and their associated kernel threads. These race conditions can result in a use-after-free scenario when stopping streaming, potentially allowing local users with access to /dev/video0 to escalate privileges if the driver is loaded.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit targeting a vulnerability in the Linux kernel's vivid driver. The main file, vivid.c, is a C program that attempts to trigger a race condition in the vivid driver by using multiple threads and userfaultfd-based memory manipulation. The exploit is designed to crash the kernel (denial of service) and may be further developed for privilege escalation, as it manipulates kernel memory structures and references kernel symbols such as prepare_kernel_cred and commit_creds. The exploit requires local access and at least two CPUs to function, as it relies on racing conditions. The vivid.h file provides structure definitions for interacting with the driver. Additionally, there is a hello.html file containing JavaScript that makes an HTTP request to http://106.55.240.79:4444, which may be used for exfiltration or as a callback mechanism, but is not directly related to the kernel exploit. The repository is a PoC and not weaponized, as it requires manual setup and does not provide a fully automated privilege escalation payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.