CVE-2019-15917Use After Free in Kernel

CWE-416Use After Free7 documents6 sources
Severity
7.0HIGHNVD
EPSS
0.1%
top 75.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateMay 24

Description

An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel3.12.613.13+4
Debianlinux/linux_kernel< 4.19.37-1+3
debiandebian/linux< linux 4.19.37-1 (bookworm)
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-whjm-35vr-w8jj: An issue was discovered in the Linux kernel before 52022-05-24
OSV
CVE-2019-15917: An issue was discovered in the Linux kernel before 52019-09-04

📋Vendor Advisories

2
Red Hat
kernel: use-after-free in drivers/bluetooth/hci_ldisc.c2019-09-04
Debian
CVE-2019-15917: linux - An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-f...2019

💬Community

2
Bugzilla
CVE-2019-15917 kernel: use-after-free in drivers/bluetooth/hci_ldisc.c2019-10-09
Bugzilla
CVE-2019-15917 kernel: use-after-free in drivers/bluetooth/hci_ldisc.c [fedora-all]2019-10-09