4.9
CVSSv2

CVE-2019-15291

Published: 20/08/2019 Updated: 06/09/2019
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.6 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

An issue exists in the Linux kernel up to and including 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

Mailing Lists

Hi! I've previously reported vulnerabilities in the Linux kernel USB drivers on this list [1] found with syzkaller [2] The USB fuzzing project has been on hold for a while, but has been resumed earlier this year Here's a new bunch of 15 CVEs As an experiment this time I've requested CVEs for 2 bugs (CVE-2019-15290, CVE-2019-15291) that haven't ...
On Tue, Aug 20, 2019 at 08:20:34PM +0200, Andrey Konovalov wrote: Thanks for filing CVEs for these FWIW, link [3] seems to be missing some of the USB bugs since it only includes bugs seen on the "ci2-upstream-usb" syzbot manager, when in fact USB bugs are also being reported from the "ci-upstream-kmsan-gce" manager Based on my categorization ...