In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP packets.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-5814.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.133"
}
]
},
{
"events": [
{
"introduced": "4.5"
},
{
"last_affected": "4.9.102"
}
]
},
{
"events": [
{
"introduced": "4.10"
},
{
"last_affected": "4.14.43"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"last_affected": "4.16.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.04"
}
]
}
]