CVE-2019-16233: Null Pointer Dereference
A flaw was found in the Linux kernel. A NULL pointer dereference flaw was found in the QLOGIC drivers for HBA. A call to allocworkqueue return was not validated and can cause a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
A NULL pointer dereference flaw was found in qla2x00probeone in drivers/scsi/qla2xxx/qlaos.c in Qlogic drivers for HBA. Here a call to allocworkqueue return was not validated and this can cause a denial of service at the time of failure. This could allow an attacker to crash the system or leak kernel internal information.
Reference: https://lkml.org/lkml/2019/9/9/487
— Red Hat
drivers/scsi/qla2xxx/qlaos.c in the Linux kernel 5.2.14 does not check the allocworkqueue return value, leading to a NULL pointer dereference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.rt56.1131.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.rt7.54.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
Linux kernel (drivers/scsi/qla2xxx/qla_os.c)to a version that resolves this vulnerability.Fixed in 5.2.14
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-16233?
The severity of CVE-2019-16233 is critical, primarily affecting system availability due to a NULL pointer dereference.
How do I fix CVE-2019-16233?
To fix CVE-2019-16233, update to the fixed kernel versions provided by your distribution such as Red Hat Enterprise Linux or Ubuntu.
Which versions are affected by CVE-2019-16233?
CVE-2019-16233 affects multiple versions of the Linux kernel, specifically those before the patched versions indicated by your distribution.
What type of vulnerability is CVE-2019-16233?
CVE-2019-16233 is a NULL pointer dereference vulnerability found in the QLOGIC drivers.
What systems are impacted by CVE-2019-16233?
CVE-2019-16233 impacts systems running vulnerable versions of the Linux kernel across various distributions like Red Hat and Ubuntu.