Severity
6.5MEDIUM
EPSS
0.5%
top 35.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateApr 30

Description

A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

Debianlinux< 4.19.37-1+3
CVEListV5linux/linuxbefore 5.1-rc1, fixed in 5.1-rc1+1

Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 5.0, 6.0, 7.0, 8.0, 8.1, 8.2, 8.4, 7, 8

Patches

🔴Vulnerability Details

4
GHSA
GHSA-mxj7-853v-cxhh: A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 52022-04-30
CVEList
CVE-2019-3459: A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 52019-04-11
OSV
CVE-2019-3459: A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 52019-04-11
OSV
linux-hwe, linux-azure vulnerabilities2019-04-02

📋Vendor Advisories

10
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel (HWE) vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel vulnerabilities2019-04-02
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2019-04-02

💬Community

2
Bugzilla
CVE-2019-3459 CVE-2019-3460 kernel: various flaws [fedora-all]2019-01-14
Bugzilla
CVE-2019-3459 kernel: Heap address information leak while using L2CAP_GET_CONF_OPT2019-01-03