CVE-2019-15219: Null Pointer Dereference
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-15219.
What is the severity of CVE-2019-15219?
The severity of CVE-2019-15219 is medium with a CVSSv3 score of 4.6.
Which software is affected by CVE-2019-15219?
The Linux kernel versions before 5.1.8, as well as Netapp Baseboard Management Controller H410c Firmware, Canonical Ubuntu Linux (versions 16.04, 18.04, 19.04), Debian Debian Linux 8.0, and openSUSE Leap (versions 15.0, 15.1) are affected by CVE-2019-15219.
What is the cause of CVE-2019-15219?
CVE-2019-15219 is caused by a NULL pointer dereference in the drivers/usb/misc/sisusbvga/sisusb.c driver when a malicious USB device is connected.
Are any patches or fixes available for CVE-2019-15219?
Yes, patches and fixes are available for CVE-2019-15219. It is recommended to update to Linux kernel version 5.1.8 or later to mitigate this vulnerability.