CVE-2019-15098: Null Pointer Dereference
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15098?
CVE-2019-15098 is a moderate severity vulnerability due to a NULL pointer dereference in the Linux kernel.
How do I fix CVE-2019-15098?
To fix CVE-2019-15098, you should upgrade to a kernel version higher than 5.2.9.
Which systems are affected by CVE-2019-15098?
CVE-2019-15098 affects various versions of the Linux kernel up to 5.2.9 and certain NetApp products including Active IQ services.
Does CVE-2019-15098 have any known exploits?
As of the last update, there are no publicly known exploits specifically targeting CVE-2019-15098.
Is there a patch available for CVE-2019-15098?
Yes, patches are available in kernel versions 5.10.223-1, 5.10.226-1, 6.1.119-1, and later.