CVE-2019-15212: Double Free
Published Aug 19, 2019
·Updated
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
Affected Software
18 affected componentsFixes available
Linux Linux kernel<5.1.8
NetApp H410c Firmware
NetApp H410c
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Data Availability Services
NetApp Solidfire \& Hci Management Node
NetApp Solidfire Baseboard Management Controller
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
Debian Debian Linux=8.0
openSUSE Leap=15.0
openSUSE Leap=15.1
All of the following
NetApp H410c Firmware
NetApp H410c
NetApp Baseboard Management Controller H410c Firmware
NetApp Baseboard Management Controller H410c
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Event History
Aug 19, 2019
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:19 PM
Description
May 2, 2025
Data Sourced
via Ubuntu·04:08 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-15212?
CVE-2019-15212 has a high severity rating due to the potential exploitation via a malicious USB device, leading to a double-free vulnerability.
2
How do I fix CVE-2019-15212?
To fix CVE-2019-15212, upgrade to the Linux kernel version 5.1.8 or later.
3
What systems are affected by CVE-2019-15212?
CVE-2019-15212 affects Linux kernel versions prior to 5.1.8, as well as various firmware provided by NetApp.
4
What does CVE-2019-15212 exploit?
CVE-2019-15212 exploits a vulnerability in the rio500 USB driver within the Linux kernel.
5
Who is affected by CVE-2019-15212?
Users and systems running affected versions of the Linux kernel or specific NetApp firmware are at risk due to CVE-2019-15212.