In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usbaudioprobe in sound/usb/card.c.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-19824.json"
[
{
"digest": {
"function_hash": "166373707627381993425626148838488919484",
"length": 2500.0
},
"signature_version": "v1",
"target": {
"file": "sound/usb/card.c",
"function": "usb_audio_probe"
},
"signature_type": "Function",
"id": "CVE-2018-19824-5b90e8c7",
"source": "https://github.com/torvalds/linux/commit/5f8cf712582617d523120df67d392059eaf2fc4b",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"262716766667325143656144305638043911769",
"167840789105495793641327047307936398327",
"287588678027689922116077540691963245755",
"207041702666367952249121875189796303477",
"329352471166442562096355071855372465252",
"159300237294899467434314791579235676154",
"272202861644401360680086783689164659741"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "sound/usb/card.c"
},
"signature_type": "Line",
"id": "CVE-2018-19824-9b736994",
"source": "https://github.com/torvalds/linux/commit/5f8cf712582617d523120df67d392059eaf2fc4b",
"deprecated": false
}
]