First published: Mon Dec 23 2019(Updated: )
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=5.4.6 | |
Debian | =8.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Cloud Backup | ||
NetApp Data Availability Services | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.2 | |
NetApp FAS/AFF Baseboard Management Controller | ||
NetApp HCI Baseboard Management Controller | =h610s | |
NetApp SolidFire & HCI Management Node | ||
NetApp SteelStore Cloud Integrated Storage | ||
NetApp FAS/AFF Baseboard Management Controller | =a700s | |
NetApp SolidFire | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19947 is classified as a moderate severity vulnerability due to potential information leaks of uninitialized memory.
To fix CVE-2019-19947, upgrade to Linux kernel version 5.10.223-1 or later as specified in the remediation guidelines.
CVE-2019-19947 affects Linux kernel versions up to 5.4.6, including specific Debian and Ubuntu distributions.
CVE-2019-19947 is an information disclosure vulnerability occurring within the kvaser_usb_leaf.c driver.
CVE-2019-19947 was publicly disclosed before the patch was released, but it is no longer considered a zero-day as fixes are available.