In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19523.json"
[
{
"id": "CVE-2019-19523-ead2b8a2",
"target": {
"function": "adu_disconnect",
"file": "drivers/usb/misc/adutux.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@44efc269db7929f6275a1fa927ef082e533ecde0",
"digest": {
"function_hash": "212578619819128523483822250193822933412",
"length": 330.0
},
"signature_type": "Function"
},
{
"id": "CVE-2019-19523-ecdaa8fa",
"target": {
"file": "drivers/usb/misc/adutux.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@44efc269db7929f6275a1fa927ef082e533ecde0",
"digest": {
"threshold": 0.9,
"line_hashes": [
"13625024364140770831181953647598228354",
"218085868283332826672312356944693714609",
"97418432910018022974657174228722490931",
"199983789119199236976104807514948335247",
"322749726863088399753260116900955229675",
"16070669409910795789195360442034555617",
"285441873410185136207577997290871094477",
"265880292367431094469119699665329515406",
"270274092113139541142529703975782354995"
]
},
"signature_type": "Line"
}
]