CVE-2019-12615: Null Pointer Dereference
An issue was discovered in getvdevportnodeinfo in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdupconst of nodeinfo->vdevport.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12615?
CVE-2019-12615 is a vulnerability in the Linux kernel that allows an attacker to cause a denial of service (NULL pointer dereference and system crash).
How severe is CVE-2019-12615?
CVE-2019-12615 has a severity rating of 7.5, which is considered high.
Which software is affected by CVE-2019-12615?
CVE-2019-12615 affects the Linux kernel versions 2.6.12.1 to 4.14.130, 4.19 to 4.19.56, and 5.1 to 5.1.15.
How can I fix CVE-2019-12615?
To fix CVE-2019-12615, you should update your Linux kernel to a version that is not vulnerable.
Where can I find more information about CVE-2019-12615?
You can find more information about CVE-2019-12615 on the following websites: http://www.securityfocus.com/bid/108549, https://git.kernel.org/pub/scm/linux/kernel/git/davem/sparc.git/commit/?id=80caf43549e7e41a695c6d1e11066286538b336f, and https://security.netapp.com/advisory/ntap-20190710-0002/