Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12614

Опубликовано: 03 июн. 2019
Источник: debian
EPSS Низкий

Описание

An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.3.7-1package
linuxfixed4.19.98-1busterpackage
linuxfixed4.9.210-1stretchpackage

Примечания

  • https://lkml.org/lkml/2019/6/3/526

  • This is a potential null pointer dereference that looks like it can

  • only be invoked by root or the hypervisor. Probably no security impact.

EPSS

Процентиль: 31%
0.00116
Низкий

Связанные уязвимости

CVSS3: 4.1
ubuntu
около 6 лет назад

An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

CVSS3: 4.1
redhat
около 6 лет назад

An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

CVSS3: 4.1
nvd
около 6 лет назад

An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

github
около 3 лет назад

An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

CVSS3: 4.1
fstec
около 6 лет назад

Уязвимость функции dlpar_parse_cc_property (arch/powerpc/platforms/pseries/dlpar.c) ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 31%
0.00116
Низкий