Unrated severityNVD Advisory· Published Jan 25, 2011· Updated Apr 29, 2026
CVE-2011-0640
CVE-2011-0640
Description
The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.
Affected products
1- cpe:2.3:a:udev_project:udev:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- news.cnet.com/8301-27080_3-20028919-245.htmlnvdBroken Link
- www.blackhat.com/html/bh-dc-11/bh-dc-11-briefings.htmlnvdNot Applicable
- www.cs.gmu.edu/~astavrou/publications.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.