CVE-2019-15504
published 2019-08-23CVE-2019-15504: drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.31%
90.1th percentile
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 5.2.17-1 (bookworm) | linux 5.2.17-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 0 < 5.2.17-1 | 5.2.17-1 |
| linux | linux_kernel | >= 4.17 < 4.19.74 | 4.19.74 |
| linux | linux_kernel | >= 4.20 < 5.2.16 | 5.2.16 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-10-22·CVSS 7.8
CVE-2019-14814 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4157-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu
18.04 LTS.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A loca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-10-17·CVSS 7.8
CVE-2019-14814 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A local attacker with write access to /dev/kvm could
use this to cause a denial of service (system crash). (CVE-2019-14821)
Hui Peng and Mathias Payer discovered that the 91x Wi-Fi driver in the
Linux kernel did not p
Red Hat
kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device
vendor_redhat·2019-08-23·CVSS 9.8
CVE-2019-15504 [CRITICAL] CWE-416 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device
kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-15504: linux - drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a D...
vendor_debian·2019·CVSS 9.8
CVE-2019-15504 [CRITICAL] CVE-2019-15504: linux - drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a D...
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
Scope: local
bookworm: resolved (fixed in 5.2.17-1)
bullseye: resolved (fixed in 5.2.17-1)
forky: resolved (fixed in 5.2.17-1)
sid: resolved (fixed in 5.2.17-1)
trixie: resolved (fixed in 5.2.17-1)
GHSA
GHSA-c27q-jw2x-f8mw: drivers/net/wireless/rsi/rsi_91x_usb
ghsa_unreviewed·2022-05-24
CVE-2019-15504 [CRITICAL] CWE-415 GHSA-c27q-jw2x-f8mw: drivers/net/wireless/rsi/rsi_91x_usb
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
OSV
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
osv·2019-10-22·CVSS 7.8
[HIGH] linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
USN-4157-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu
18.04 LTS.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A local attacker with write access to /dev/kvm co
OSV
CVE-2019-15504: drivers/net/wireless/rsi/rsi_91x_usb
osv·2019-08-23·CVSS 9.8
CVE-2019-15504 [CRITICAL] CVE-2019-15504: drivers/net/wireless/rsi/rsi_91x_usb
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
Kernel
rsi: fix a double free bug in rsi_91x_deinit()
kernel_security·2019-08-19·CVSS 9.8
CVE-2019-15504 [CRITICAL] rsi: fix a double free bug in rsi_91x_deinit()
rsi: fix a double free bug in rsi_91x_deinit()
`dev` (struct rsi_91x_usbdev *) field of adapter
(struct rsi_91x_usbdev *) is allocated and initialized in
`rsi_init_usb_interface`. If any error is detected in information
read from the device side, `rsi_init_usb_interface` will be
freed. However, in the higher level error handling code in
`rsi_probe`, if error is detected, `rsi_91x_deinit` is called
again, in which `dev` will be freed again, resulting double free.
This patch fixes the double free by removing the free operation on
`dev` in `rsi_init_usb_interface`, because `rsi_91x_deinit` is also
used in `rsi_disconnect`, in that code path, the `dev` field is not
(and thus needs to be) freed.
This bug was found in v4.19, but is also present in the latest version
of kernel. Fixes CVE-2019-
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-15504 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device
bugzilla·2019-08-29·CVSS 9.8
CVE-2019-15504 [CRITICAL] CVE-2019-15504 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device
CVE-2019-15504 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device
A vulnerability was found in drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/kvalo/wireless-drivers.git/commit/?id=8b51dc7291473093c821195c4b6af85fadedbc2f
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1746726]
---
Note:
This flaw is classified in the attack vector (local) that the device appears to the kernel. Local attacks would not be considered remote attacks if the attacker must first ssh in.
Red Hat Enterprise Enterprise Linux does not ship a kernel with this network device enable
Bugzilla
CVE-2019-15504 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device [fedora-all]
bugzilla·2019-08-29·CVSS 9.8
CVE-2019-15504 [CRITICAL] CVE-2019-15504 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device [fedora-all]
CVE-2019-15504 kernel: double free in drivers/net/wireless/rsi/rsi_91x_usb.c via crafted USB device [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/https://lore.kernel.org/lkml/20190819220230.10597-1-benquike%40gmail.com/https://security.netapp.com/advisory/ntap-20190905-0002/https://support.f5.com/csp/article/K33554143https://support.f5.com/csp/article/K33554143?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4157-1/https://usn.ubuntu.com/4157-2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3RUDQJXRJQVGHCGR4YZWTQ3ECBI7TXH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4JZ6AEUKFWBHQAROGMQARJ274PQP2QP/https://lore.kernel.org/lkml/20190819220230.10597-1-benquike%40gmail.com/https://security.netapp.com/advisory/ntap-20190905-0002/https://support.f5.com/csp/article/K33554143https://support.f5.com/csp/article/K33554143?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4157-1/https://usn.ubuntu.com/4157-2/
2019-08-23
Published