4.6
CVSSv3

CVE-2019-15219

Published: 19/08/2019 Updated: 09/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.6 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 437
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

An issue exists in the Linux kernel prior to 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

netapp h410c firmware -

netapp data availability services -

netapp solidfire & hci management node -

netapp active iq unified manager -

netapp solidfire baseboard management controller -

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 16.04

debian debian linux 8.0

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Impact: Moderate Public Date: 2019-08-19 CWE: CWE-476 Bugzilla: 1745536: CVE-2019-15219 kernel: null po ...

Mailing Lists

On Thu, Aug 22, 2019 at 1:00 PM John Haxby <johnhaxby () oracle com> wrote: Yeah, I don't think those DoS USB bugs are in any way useful to an attacker I've looked at existing USB CVEs before I've started reporting these, and MITRE does assign CVEs to such issues I don't know whether they should warrant CVEs or not On a side note, curr ...
Hi! I've previously reported vulnerabilities in the Linux kernel USB drivers on this list [1] found with syzkaller [2] The USB fuzzing project has been on hold for a while, but has been resumed earlier this year Here's a new bunch of 15 CVEs As an experiment this time I've requested CVEs for 2 bugs (CVE-2019-15290, CVE-2019-15291) that haven't ...
On Thu, Aug 22, 2019 at 10:04:42AM +0100, John Haxby wrote: In the past we have considered Denial Of Service only USB vulnerabilites as non-issues, as physical access can cause the same USB Vulnerabilities where you can achieve code execution by a malicious USB device are something else though and in my opinion warrant a CVE Ciao, Marcus ...
Are these even realistic? If I'm going to leave malicious USB devices in the parking lot for mischief am I going to rely on the unknown victim running a Linux distro with the requisite kernel modules or am I going to just drop a cheap and near-universal USB killer? If I'm going to be connecting the USB device to unguarded laptops myself to cra ...
<nod> I carefully didn't quote any of the UAF bugs -- those definitely do warrant a CVE Null pointer dereference is a DoS jch ...