CVE-2019-9455: Infoleak
A flaw was found in the Linux kernel's video driver. A kernel pointer lead, due to a WARNON statement could lead to a local information disclosure with system execution privileges. User interaction is not needed for exploitation. The highest threat from this vulnerability is to data confidentiality.
Other sources
A vulnerability was found in the video driver in Kernel where there is a kernel pointer leak due to a WARNON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
References:
https://source.android.com/security/bulletin/pixel/2019-09-01
— Red Hat
In the Android kernel in the video driver there is a kernel pointer leak due to a WARNON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-9455?
CVE-2019-9455 has a high severity rating due to its potential impact on data confidentiality.
How do I fix CVE-2019-9455?
To resolve CVE-2019-9455, upgrade to the appropriate patched kernel version, either kernel-rt 0:4.18.0-240.rt7.54.el8 or kernel 0:4.18.0-240.el8.
What are the potential impacts of CVE-2019-9455?
CVE-2019-9455 can result in local information disclosure with system execution privileges.
Is user interaction required to exploit CVE-2019-9455?
No, CVE-2019-9455 can be exploited without any user interaction.
Which software is affected by CVE-2019-9455?
CVE-2019-9455 affects specific versions of the Linux kernel, including Red Hat kernel-rt and kernel packages, as well as Google Android and openSUSE Leap 15.1.