Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15211

Опубликовано: 19 авг. 2019
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

A use-after-free flaw was found in the Linux kernel. A local attacker who was able to disconect a USB raremono v4l radio device could trigger a use-after-free condition where they could abuse this flaw to corrupt memory, crash the system, or escalate privileges

Отчет

This module is not included in the Red Hat Enterprise Linux kernels.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise MRG 2kernelNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1743544kernel: use-after-free in drivers/media/v4l2-core/v4l2-dev.c

EPSS

Процентиль: 30%
0.00109
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 6 лет назад

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
nvd
больше 6 лет назад

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
debian
больше 6 лет назад

An issue was discovered in the Linux kernel before 5.2.6. There is a u ...

CVSS3: 4.6
github
больше 3 лет назад

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
fstec
больше 6 лет назад

Уязвимость драйвера drivers/media/v4l2-core/v4l2-dev.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00109
Низкий

7.3 High

CVSS3