CVE-2019-0161
edk2: stack overflow in XHCI causing denial of service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.
Desbordamiento de pila en XHCI para EDK II podrÃa permitir que un usuario no autenticado provoque una denegación de servicio mediante acceso local.
It was discovered that EDK II did not check the buffer length in XHCI, which could lead to a stack overflow. A local attacker could potentially use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Laszlo Ersek discovered that EDK II incorrectly handled recursion. A remote attacker could possibly use this issue to cause EDK II to consume resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-13 CVE Reserved
- 2019-03-27 CVE Published
- 2024-08-04 CVE Updated
- 2025-08-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-787: Out-of-bounds Write
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2021/04/msg00032.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://edk2-docs.gitbooks.io/security-advisory/content/xhci-stack-local-stack-overflow.html | 2023-11-07 |