First published: Mon Aug 19 2019(Updated: )
An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card disconnection causes certain data structures to be deleted too early. This is related to sound/core/init.c and sound/core/info.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Linux Kernel | <5.0.10 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15214 is classified as a high severity vulnerability due to the risk of a use-after-free condition in the Linux kernel sound subsystem.
CVE-2019-15214 affects Linux kernel versions prior to 5.0.10, as well as specific versions of Google Android and Ubuntu Linux.
To fix CVE-2019-15214, update the Linux kernel to version 5.0.10 or later, or apply the necessary patches provided by your distribution.
CVE-2019-15214 is a use-after-free vulnerability that occurs in the sound subsystem of the Linux kernel.
As of now, there are no publicly known exploits specifically targeted at CVE-2019-15214.