PT-2019-5417 · Linux+3 · Linux Kernel+3

Published

2019-02-27

·

Updated

2021-05-28

·

CVE-2019-12818

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.20.15
Description The issue is related to the nfc llcp build tlv function in the Linux kernel, which may return NULL. If the caller does not check for this, it will trigger a null pointer dereference, causing a denial of service. This can be exploited by a remote attacker to cause a service disruption.
Recommendations For Linux kernel versions prior to 4.20.15, update to version 4.20.15 or later to resolve the issue. As a temporary workaround, consider implementing checks for NULL return values from the nfc llcp build tlv function to prevent null pointer dereferences.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1415
ALT-PU-2019-1506
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-02920
CVE-2019-12818
OPENSUSE-SU-2019:1571-1
OPENSUSE-SU-2019:1579-1
OPENSUSE-SU-2019_1570-1
OPENSUSE-SU-2019_1571-1
OPENSUSE-SU-2019_1579-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:1823-1
SUSE-SU-2019:1823-2
SUSE-SU-2019:1829-1
SUSE-SU-2019:1851-1
SUSE-SU-2019:1852-1
SUSE-SU-2019:1855-1
SUSE-SU-2019:1870-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
USN-4094-1
USN-4118-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu