CVE-2019-15926: Critical severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6klwmipstreamtimeouteventrx and ath6klwmicaceventrx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.2.3 - Compensating control
Apply a compensating control by reducing exposure of affected systems until the kernel is updated (e.g., restrict network access to systems running the vulnerable Linux kernel).
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15926?
CVE-2019-15926 has a severity rating that indicates it can lead to out of bounds access, potentially impacting system stability.
How do I fix CVE-2019-15926?
To fix CVE-2019-15926, update the Linux kernel to version 5.2.3 or later.
Which versions of the Linux kernel are affected by CVE-2019-15926?
CVE-2019-15926 affects the Linux kernel versions from 3.2 to 5.2.2.
Can CVE-2019-15926 be exploited remotely?
CVE-2019-15926 may allow for remote exploitation if the affected kernel is running on a device accessible from the network.
What types of systems are vulnerable to CVE-2019-15926?
Systems running various distributions of the Linux kernel within the specified version range are vulnerable to CVE-2019-15926.