PT-2019-4886 · Linux+4 · Linux Kernel+4

Published

2019-01-07

·

Updated

2023-02-24

·

CVE-2019-15927

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.20.2
Description An issue exists in the Linux kernel due to an out-of-bounds access in the build audio procunit function, located in the sound/usb/mixer.c file. This issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 4.20.2, update to version 4.20.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the sound/usb/mixer.c file or disabling the build audio procunit function until a patch is available.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1046
ALT-PU-2019-1048
ALT-PU-2019-1139
BDU:2020-01474
CESA-2019_2029
CESA-2019_3517
CVE-2019-15927
OPENSUSE-SU-2019:2173-1
OPENSUSE-SU-2019:2181-1
OPENSUSE-SU-2019_2173-1
OPENSUSE-SU-2019_2181-1
RHSA-2019:2029
RHSA-2019:3517
RHSA-2019_2029
RHSA-2019_3517
SUSE-SU-2019:14218-1
SUSE-SU-2019:2412-1
SUSE-SU-2019:2414-1
SUSE-SU-2019:2424-1
SUSE-SU-2019:2648-1
SUSE-SU-2019:2651-1
SUSE-SU-2019:2658-1
SUSE-SU-2019:2738-1
SUSE-SU-2019:2756-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2950-1
SUSE-SU-2019:2984-1
SUSE-SU-2019_14218-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse