CVE-2019-19947: Medium severity Linux Linux kernel vulnerability
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaserusb/kvaserusbleaf.c driver, aka CID-da2311a6385c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19947?
CVE-2019-19947 is classified as a moderate severity vulnerability due to potential information leaks of uninitialized memory.
How do I fix CVE-2019-19947?
To fix CVE-2019-19947, upgrade to Linux kernel version 5.10.223-1 or later as specified in the remediation guidelines.
Which Linux versions are affected by CVE-2019-19947?
CVE-2019-19947 affects Linux kernel versions up to 5.4.6, including specific Debian and Ubuntu distributions.
What type of vulnerability is CVE-2019-19947?
CVE-2019-19947 is an information disclosure vulnerability occurring within the kvaser_usb_leaf.c driver.
Is CVE-2019-19947 a zero-day vulnerability?
CVE-2019-19947 was publicly disclosed before the patch was released, but it is no longer considered a zero-day as fixes are available.