CVE-2019-20806
published 2020-05-27CVE-2019-20806: An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in…
PriorityP413medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.38%
31.5th percentile
An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| linux | linux_kernel | < 5.2 | 5.2 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c
vendor_redhat·2020-03-29·CVSS 4.4
CVE-2019-20806 [MEDIUM] CWE-476 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c
kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c
An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.
A NULL pointer dereference flaw was found in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c in the TW5864 Series Video media driver. The pointer 'vb' is assigned, but not validated before its use, and can lead to a denial of service. This flaw allows a local attacker with special user or root privileges to crash the system or leak internal kernel information.
Statement: There was not a shipped kernel version that was seen to be affected by th
Debian
CVE-2019-20806: linux - An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer ...
vendor_debian·2019·CVSS 4.4
CVE-2019-20806 [MEDIUM] CVE-2019-20806: linux - An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer ...
An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
GHSA
GHSA-2gmw-gg2v-3ffg: An issue was discovered in the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2019-20806 [MEDIUM] GHSA-2gmw-gg2v-3ffg: An issue was discovered in the Linux kernel before 5
An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.
OSV
CVE-2019-20806: An issue was discovered in the Linux kernel before 5
osv·2020-05-27·CVSS 4.4
CVE-2019-20806 [MEDIUM] CVE-2019-20806: An issue was discovered in the Linux kernel before 5
An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20806 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c
bugzilla·2020-06-01·CVSS 4.4
CVE-2019-20806 [MEDIUM] CVE-2019-20806 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c
CVE-2019-20806 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c
A NULL pointer dereference flaw was found in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c in TW5864 Series Video media driver. Here a pointer 'vb' assigned but not validated before its use can lead to a denial of service (DoS) problem. This flaw could allow a local attacker with special user privilege (or root) to crash the system or leak internal kernel information.
Reference and upstream commit:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2e7682ebfc750177a4944eeb56e97a3f05734528
Discussion:
Created kernel tracking bugs for this issue:
Affects: fed
Bugzilla
CVE-2019-20806 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c [fedora-all]
bugzilla·2020-06-01·CVSS 4.4
CVE-2019-20806 [MEDIUM] CVE-2019-20806 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c [fedora-all]
CVE-2019-20806 kernel: NULL pointer dereference in tw5864_handle_frame function in drivers/media/pci/tw5864/tw5864-video.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2e7682ebfc750177a4944eeb56e97a3f05734528https://github.com/torvalds/linux/commit/2e7682ebfc750177a4944eeb56e97a3f05734528https://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20200619-0001/https://www.debian.org/security/2020/dsa-4698http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.htmlhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2e7682ebfc750177a4944eeb56e97a3f05734528https://github.com/torvalds/linux/commit/2e7682ebfc750177a4944eeb56e97a3f05734528https://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20200619-0001/https://www.debian.org/security/2020/dsa-4698
2020-05-27
Published