CVE-2018-19854: Canonical Ubuntu Linux
Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Linux Linux Kernel: before 4.19.3 (fixed in 4.19.3)
Published 2018-12-04. Last modified 2026-06-17.