CVE-2019-15215: Use After Free
Published Aug 19, 2019
·Updated
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2usb.c driver.
Affected Software
18 affected componentsFixes available
Linux Linux kernel<5.2.6
NetApp H410c Firmware
NetApp H410c
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Data Availability Services
NetApp Solidfire \& Hci Management Node
NetApp Solidfire Baseboard Management Controller
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
Debian Debian Linux=8.0
openSUSE Leap=15.0
openSUSE Leap=15.1
NetApp Baseboard Management Controller H410c Firmware
NetApp Baseboard Management Controller H410c
All of the following
NetApp H410c Firmware
NetApp H410c
debian/linux
6.1.176-16.1.187-16.12.107-17.1.13-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1
Event History
Aug 19, 2019
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:20 PM
Description
Sep 10, 2026
Data Sourced
via Ubuntu·11:44 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2026
Data Sourced
via Debian·11:47 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-15215?
CVE-2019-15215 is considered a high severity vulnerability due to its potential to be exploited by malicious USB devices.
2
How do I fix CVE-2019-15215?
To fix CVE-2019-15215, upgrade to a Linux kernel version of 5.2.6 or later.
3
Which Linux kernel versions are affected by CVE-2019-15215?
CVE-2019-15215 affects Linux kernel versions prior to 5.2.6.
4
What types of devices are implicated in CVE-2019-15215?
CVE-2019-15215 is associated with vulnerabilities that can be exploited by malicious USB devices.
5
Is the CVE-2019-15215 vulnerability present in Ubuntu 16.04?
Yes, CVE-2019-15215 affects Ubuntu 16.04 if it is running a kernel version lower than 5.2.6.