An issue was discovered in the Linux kernel before 4.19.3. cryptoreportone() and related functions in crypto/cryptouser.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIGCRYPTO_USER kconfig option).
[
{
"id": "CVE-2018-19854-de04dbb5",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"287657633883815589574315683014073036264",
"122787649557083584605376517127332867147",
"305994582563881038676730219719037496445",
"107666609562011087771476166984822510327",
"88144917770932138972844907039003139943",
"193149682905497889055261260030609855382",
"69050346510315142781072532527522339772",
"198058694024563232043224450977441518260",
"275091948911193715892157377906318250699",
"249708295326731019376639279791989695540",
"203117222871911007299620358591642259449",
"18103542071284494877460423896763828000",
"254121346934718882898007682555191659857",
"290060529334059412920626917476732460408",
"274621287738373232666187525829142581173",
"325918466977292926121966334011372108489",
"269065887273706347775049406297701224582",
"181856369817477778143994978939454355652",
"137787925621949434969375712270553695859",
"251336010037387794899033322665581695429",
"180400931401110125635867631710548897388",
"130837989432950128595080366179871352449",
"278121227617864476123179861339765253494",
"308067708744610608377970523569055105123",
"258605902225861203999864586419376584988",
"248602973763282540368182543456065544111",
"275030887251383297537121453149234626471",
"335602557874544141954986895040044775239",
"299750612198941479286834778529992385178",
"52291485503222059613054168539638926036",
"224749205640555601137998134738124405169"
]
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f43f39958beb206b53292801e216d9b8a660f087",
"signature_type": "Line",
"target": {
"file": "crypto/crypto_user_base.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19854.json"
[
{
"id": "CVE-2018-19854-5e5f47ce",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"287657633883815589574315683014073036264",
"122787649557083584605376517127332867147",
"305994582563881038676730219719037496445",
"107666609562011087771476166984822510327",
"88144917770932138972844907039003139943",
"193149682905497889055261260030609855382",
"69050346510315142781072532527522339772",
"198058694024563232043224450977441518260",
"275091948911193715892157377906318250699",
"249708295326731019376639279791989695540",
"203117222871911007299620358591642259449",
"18103542071284494877460423896763828000",
"254121346934718882898007682555191659857",
"290060529334059412920626917476732460408",
"274621287738373232666187525829142581173",
"325918466977292926121966334011372108489",
"269065887273706347775049406297701224582",
"181856369817477778143994978939454355652",
"137787925621949434969375712270553695859",
"251336010037387794899033322665581695429",
"180400931401110125635867631710548897388",
"130837989432950128595080366179871352449",
"278121227617864476123179861339765253494",
"308067708744610608377970523569055105123",
"258605902225861203999864586419376584988",
"248602973763282540368182543456065544111",
"275030887251383297537121453149234626471",
"335602557874544141954986895040044775239",
"299750612198941479286834778529992385178",
"52291485503222059613054168539638926036",
"224749205640555601137998134738124405169"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/f43f39958beb206b53292801e216d9b8a660f087",
"signature_type": "Line",
"target": {
"file": "crypto/crypto_user_base.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19854.json"