CVE-2019-12615
Last modified
CVE-2019-12615 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).. EPSS estimates a 3.57% chance of exploitation in the next 30 days.
Description
An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 2.6.12.1, < 4.14.130 | — |
| Linux | Linux Kernel | >= 4.19, < 4.19.56 | — |
| Linux | Linux Kernel | >= 5.1, < 5.1.15 | — |
| Linux | Linux Kernel | 2.6.12 | Rc2 |
| Linux | Linux Kernel | 5.2 | Rc1 |
| Netapp | Aff A700s Firmware | All versions | — |
| Netapp | Active Iq Unified Manager | >= 9.5 | — |
| Netapp | Hci Management Node | All versions | — |
| Netapp | Solidfire | All versions | — |
| Netapp | Cn1610 Firmware | All versions | — |
| Netapp | H610s Firmware | All versions | — |
References
- http://www.securityfocus.com/bid/108549Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20190710-0002/Third Party Advisory
- https://support.f5.com/csp/article/K60924046Third Party Advisory
- http://www.securityfocus.com/bid/108549Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20190710-0002/Third Party Advisory
- https://support.f5.com/csp/article/K60924046Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12615?
How severe is CVE-2019-12615?
How do I fix CVE-2019-12615?
Are you affected by CVE-2019-12615?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
