First published: Tue Apr 23 2019(Updated: )
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 4.19.249-2 4.19.289-2 5.10.197-1 5.10.191-1 6.1.66-1 6.1.52-1 6.5.13-1 6.6.8-1 | |
Linux Linux kernel | <3.16.66 | |
Linux Linux kernel | >=3.17<3.18.139 | |
Linux Linux kernel | >=3.19<4.4.179 | |
Linux Linux kernel | >=4.5<4.9.169 | |
Linux Linux kernel | >=4.10<4.14.112 | |
Linux Linux kernel | >=4.15<4.19.35 | |
Linux Linux kernel | >=4.20<5.0.8 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =42.3 | |
Netapp Active Iq | ||
Netapp Hci Management Node | ||
Netapp Snapprotect | ||
Netapp Solidfire | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | =9.7 | |
Netapp Vasa Provider For Clustered Data Ontap | =9.7 | |
Netapp Virtual Storage Console Vmware Vsphere | =9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2019-11486.
The severity level of CVE-2019-11486 is high with a severity value of 7.
The Linux kernel versions before 5.0.8 and certain versions of Debian, openSUSE Leap, Netapp Active Iq, Netapp Hci Management Node, Netapp Snapprotect, Netapp Solidfire, Netapp Storage Replication Adapter For Clustered Data Ontap, Netapp Vasa Provider For Clustered Data Ontap, and Netapp Virtual Storage Console are affected. Please refer to the vulnerability description for specific version details.
The race condition vulnerability in the Siemens R3964 line discipline driver is considered high severity.
To fix CVE-2019-11486, update to Linux kernel version 5.0.8 or later, or apply the appropriate security patches provided by your software vendor.