First published: Fri Aug 16 2019(Updated: )
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 | |
Linux Kernel | <=5.2.9 | |
NetApp Active IQ | ||
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
netapp data availability services | ||
NetApp Element Software | ||
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15098 is a moderate severity vulnerability due to a NULL pointer dereference in the Linux kernel.
To fix CVE-2019-15098, you should upgrade to a kernel version higher than 5.2.9.
CVE-2019-15098 affects various versions of the Linux kernel up to 5.2.9 and certain NetApp products including Active IQ services.
As of the last update, there are no publicly known exploits specifically targeting CVE-2019-15098.
Yes, patches are available in kernel versions 5.10.223-1, 5.10.226-1, 6.1.119-1, and later.