CVE-2019-15925: High severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclgetmschdmodevnetbasecfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclgetm.c.
Other sources
An issue was discovered in the Linux kernel. An out of bounds access exists in the function hclgetmschdmodevnetbasecfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclgetm.c.
Reference: https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04f25edb48c441fc278ecc154c270f16966cbb90
— Red Hat
An out-of-bounds access flaw was found in the hclgeshaperparacalc driver in the Linux kernel. Access to an array with an index higher than its maximum index will lead to an out-of-bounds access vulnerability. This could affect both data confidentiality and integrity as well as system availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.rt7.54.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Fixed in 5.2.3 - Compensating control
Blacklist the affected HCLGE kernel driver module using the kernel blacklist mechanism so it will not be loaded at boot time (module will be prevented from loading until a patch is available).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-15925?
CVE-2019-15925 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-15925?
To fix CVE-2019-15925, you should upgrade your Linux kernel to versions 4.18.0-240.rt7.54.el8 or 4.18.0-240.el8 or later.
What software is affected by CVE-2019-15925?
CVE-2019-15925 affects various versions of the Linux kernel including versions between 4.14 and 5.2.3.
What type of vulnerability is CVE-2019-15925?
CVE-2019-15925 is an out of bounds access vulnerability in the Linux kernel.
Which operating systems are vulnerable to CVE-2019-15925?
CVE-2019-15925 impacts Linux distributions that use affected versions of the Linux kernel, such as Red Hat and Ubuntu.