5.5
CVSSv3

CVE-2019-12382

Published: 28/05/2019 Updated: 17/05/2024
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 437
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

An issue exists in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel up to and including 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an malicious user to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Vendor Advisories

Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 77 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
Impact: Moderate Public Date: 2019-05-24 CWE: CWE-476 Bugzilla: 1715554: CVE-2019-12382 kernel: unchec ...