CVE-2018-20169: Canonical Ubuntu Linux
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: before 3.16.63 (fixed in 3.16.63); from 3.17, before 3.18.129 (fixed in 3.18.129); from 3.19, before 4.4.167 (fixed in 4.4.167); from 4.5, before 4.9.145 (fixed in 4.9.145); from 4.10, before 4.14.88 (fixed in 4.14.88); from 4.15, before 4.19.9 (fixed in 4.19.9)
Published 2018-12-17. Last modified 2026-06-17.