First published: Mon Aug 19 2019(Updated: )
An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <5.2.1 | |
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp data availability services | ||
netapp solidfire \& hci management node | ||
netapp solidfire baseboard management controller | ||
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Debian GNU/Linux | =8.0 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
Android | ||
Linux kernel | <5.2.1 | |
netapp baseboard management controller h410c firmware | ||
netapp baseboard management controller h410c | ||
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Debian | =8.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.16-1 | |
NetApp HCI H410C Firmware | ||
NetApp HCI H410C |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15220 has a high severity rating due to the potential for remote code execution from a malicious USB device.
To fix CVE-2019-15220, upgrade your Linux kernel to version 5.2.1 or later.
CVE-2019-15220 affects Linux kernel versions prior to 5.2.1.
Yes, CVE-2019-15220 may impact certain versions of Android that utilize the affected Linux kernel.
If an immediate upgrade is not possible, consider implementing strict USB device policies to mitigate potential exploitation of CVE-2019-15220.