CVE-2019-15220: Use After Free
An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15220?
CVE-2019-15220 has a high severity rating due to the potential for remote code execution from a malicious USB device.
How do I fix CVE-2019-15220?
To fix CVE-2019-15220, upgrade your Linux kernel to version 5.2.1 or later.
Which Linux versions are affected by CVE-2019-15220?
CVE-2019-15220 affects Linux kernel versions prior to 5.2.1.
Does CVE-2019-15220 impact Android devices?
Yes, CVE-2019-15220 may impact certain versions of Android that utilize the affected Linux kernel.
What should I do if I cannot immediately upgrade for CVE-2019-15220?
If an immediate upgrade is not possible, consider implementing strict USB device policies to mitigate potential exploitation of CVE-2019-15220.