PT-2019-4476 · Linux+5 · Linux Kernel+5

Published

2019-03-19

·

Updated

2021-05-28

·

CVE-2019-19543

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.1.6
Description The issue is related to a use-after-free error in the serial ir init module() function, located in drivers/media/rc/serial ir.c. This error can potentially allow an attacker to compromise the integrity, confidentiality, and availability of protected information.
Recommendations For Linux kernel versions prior to 5.1.6, update to version 5.1.6 or later to resolve the issue. As a temporary workaround, consider disabling the serial ir init module() function until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4431
ALT-PU-2019-2024
ALT-PU-2019-2036
ALT-PU-2019-2120
ALT-PU-2019-2311
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-00294
CESA-2020_4431
CESA-2020_4609
CVE-2019-19543
OPENSUSE-SU-2019:2675-1
OPENSUSE-SU-2019_2675-1
RHSA-2020:4431
RHSA-2020:4609
RHSA-2020_4431
RHSA-2020_4609
SUSE-SU-2019:3289-1
SUSE-SU-2019:3316-1
SUSE-SU-2019:3317-1
SUSE-SU-2019:3372-1
SUSE-SU-2019:3381-1
SUSE-SU-2019:3389-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0613-1

Affected Products

Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Suse