cbcvebase.
CVE-2019-25162
published 2024-02-26

CVE-2019-25162: In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
30.5th percentile
In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after free. [wsa: added comment to the code, added Fixes tag]

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.19.6-1 (bookworm)linux 5.19.6-1 (bookworm)
linuxlinux
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < e6412ba3b6508bdf9c074d310bf4144afa6aec1ae6412ba3b6508bdf9c074d310bf4144afa6aec1a
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < 23a191b132cd87f746c62f3dc27da33683d8582923a191b132cd87f746c62f3dc27da33683d85829
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < 871a1e94929a27bf6e2cd99523865c840bbc2d87871a1e94929a27bf6e2cd99523865c840bbc2d87
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < 81cb31756888bb062e92d2dca21cd629d77a46a981cb31756888bb062e92d2dca21cd629d77a46a9
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < 35927d7509ab9bf41896b7e44f639504eae08af735927d7509ab9bf41896b7e44f639504eae08af7
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < e8e1a046cf87c8b1363e5de835114f2779e2aaf4e8e1a046cf87c8b1363e5de835114f2779e2aaf4
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < 12b0606000d0828630c033bf0c74c748464fe87d12b0606000d0828630c033bf0c74c748464fe87d
linuxlinux>= 611e12ea0f121a31d9e9c4ce2a18a77abc2f28d6 < e4c72c06c367758a14f227c847f9d623f1994ecfe4c72c06c367758a14f227c847f9d623f1994ecf
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 4.4.0-253.2874.4.0-253.287
linuxlinux_kernel>= 4.15.0 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20.0 < 5.4.2115.4.211
linuxlinux_kernel>= 4.3.0 < 4.14.2914.14.291
linuxlinux_kernel>= 5.11.0 < 5.15.615.15.61
linuxlinux_kernel>= 5.16.0 < 5.18.185.18.18
linuxlinux_kernel>= 5.19.0 < 5.19.25.19.2
linuxlinux_kernel>= 5.5.0 < 5.10.1375.10.137

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.