PT-2019-6146 · Linux+3 · Linux Kernel+3

Hui Peng

+1

·

Published

2019-08-14

·

Updated

2021-05-28

·

CVE-2019-15117

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.2.9
Description The issue is related to the parse audio mixer unit function in the sound/usb/mixer.c file of the Linux kernel, which mishandles a short descriptor, leading to out-of-bounds memory access. This can potentially allow an attacker to access confidential information or cause a denial of service.
Recommendations For Linux kernel versions through 5.2.9, update to a version newer than 5.2.9 to resolve the issue. At the moment, there is no information about other specific mitigation measures for this vulnerability.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2537
ALT-PU-2019-2545
ALT-PU-2019-2655
ALT-PU-2019-2746
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2021-06411
CVE-2019-15117
DLA-1930-1
DLA-1940-1
DSA-4531-1
OPENSUSE-SU-2019:2173-1
OPENSUSE-SU-2019:2181-1
OPENSUSE-SU-2019_2173-1
OPENSUSE-SU-2019_2181-1
SUSE-SU-2019:2263-1
SUSE-SU-2019:2299-1
SUSE-SU-2019:2412-1
SUSE-SU-2019:2414-1
SUSE-SU-2019:2424-1
SUSE-SU-2019:2648-1
SUSE-SU-2019:2651-1
SUSE-SU-2019:2658-1
SUSE-SU-2019:2738-1
SUSE-SU-2019:2756-1
SUSE-SU-2020:2526-1
USN-4147-1
USN-4162-1
USN-4162-2
USN-4163-1
USN-4163-2

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu