CVE-2019-16234: Null Pointer Dereference
drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the allocworkqueue return value, leading to a NULL pointer dereference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (drivers/net/wireless/intel/iwlwifi/pcie/trans.c)to a version that resolves this vulnerability.Fixed in 5.2.14
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16234?
CVE-2019-16234 has a moderate severity due to the potential for a NULL pointer dereference that may lead to a denial of service.
How do I fix CVE-2019-16234?
To fix CVE-2019-16234, users should update their Linux kernel to a patched version greater than 5.2.14.
Which Linux distributions are affected by CVE-2019-16234?
CVE-2019-16234 affects Linux kernel version 5.2.14, as well as specific versions of Ubuntu 16.04 and 18.04, and openSUSE Leap 15.0 and 15.1.
What are the potential impacts of CVE-2019-16234?
The potential impacts of CVE-2019-16234 include system crashes or denial of service due to kernel failure.
Is CVE-2019-16234 specific to any particular hardware?
CVE-2019-16234 is related to the Intel wireless drivers in the Linux kernel and not tied to specific hardware.