CVE-2019-11884: Canonical Ubuntu Linux

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Linux Linux Kernel: before 5.0.15 (fixed in 5.0.15)
  • Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux For Real Time: version 8.0 only
  • Red Hat Enterprise Linux For Real Time For Nfv Tus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux For Real Time Tus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only

Published 2019-05-10. Last modified 2026-06-17.