PT-2019-12801 · Linux+1 · Linux Kernel+1

Alexandros Toptsoglou

·

Published

2019-05-30

·

Updated

2024-08-05

·

CVE-2019-12454

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.1.5
Description An issue was discovered in the wcd9335 codec enable dec function in sound/soc/codecs/wcd9335.c. It uses kstrndup instead of kmemdup nul, which may allow attackers to have an unspecified impact via unknown vectors. The vendor disputes this issue as not being a vulnerability because switching to kmemdup nul() would only fix a security issue if the source string wasn't NUL-terminated, which is not the case.
Recommendations For Linux kernel versions through 5.1.5, consider updating to a version where this issue has been addressed, although the vendor does not consider it a vulnerability. As a temporary workaround, consider reviewing the usage of kstrndup and kmemdup nul in the code to ensure proper string handling. However, since the vendor disputes the vulnerability, there is no clear guidance on a fix. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2019-2024
ALT-PU-2019-2036
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
CVE-2019-12454

Affected Products

Alt Linux
Linux Kernel