First published: Mon Aug 19 2019(Updated: )
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <5.1.8 | |
Netapp Baseboard Management Controller H410c Firmware | ||
Netapp Baseboard Management Controller H410c | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Data Availability Services | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Solidfire Baseboard Management Controller | ||
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Debian Debian Linux | =8.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Netapp H410c Firmware | ||
Netapp H410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-15219.
The severity of CVE-2019-15219 is medium with a CVSSv3 score of 4.6.
The Linux kernel versions before 5.1.8, as well as Netapp Baseboard Management Controller H410c Firmware, Canonical Ubuntu Linux (versions 16.04, 18.04, 19.04), Debian Debian Linux 8.0, and openSUSE Leap (versions 15.0, 15.1) are affected by CVE-2019-15219.
CVE-2019-15219 is caused by a NULL pointer dereference in the drivers/usb/misc/sisusbvga/sisusb.c driver when a malicious USB device is connected.
Yes, patches and fixes are available for CVE-2019-15219. It is recommended to update to Linux kernel version 5.1.8 or later to mitigate this vulnerability.