CVE-2019-15214
kernel: use-after-free in sound/core/init.c and sound/core/info.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card disconnection causes certain data structures to be deleted too early. This is related to sound/core/init.c and sound/core/info.c.
Se descubrió un problema en el kernel de Linux versiones anteriores a 5.0.10. Se presenta un uso de memoria previamente liberada en el subsistema sound porque la desconexión de la tarjeta hace que ciertas estructuras de datos se eliminen demasiado pronto. Esto está relacionado con los archivos sound/core/init.c y sound/core/info.c.
A vulnerability was found in the Linux kernel’s core sound driver code. A use-after-free in a race condition between disconnection events could allow a local attacker who can trigger disconnection events (remove or add hardware) to crash the system, corrupt memory, or escalate privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-19 CVE Reserved
- 2019-08-19 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2019/08/20/2 | Mailing List | |
https://security.netapp.com/advisory/ntap-20190905-0002 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://syzkaller.appspot.com/bug?id=75903e0021cef79bc434d068b5169b599b2a46a9 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html | 2020-03-06 | |
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html | 2020-03-06 | |
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10 | 2020-03-06 | |
https://usn.ubuntu.com/4115-1 | 2020-03-06 | |
https://usn.ubuntu.com/4118-1 | 2020-03-06 | |
https://access.redhat.com/security/cve/CVE-2019-15214 | 2020-03-31 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1743591 | 2020-03-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | < 5.0.10 Search vendor "Linux" for product "Linux Kernel" and version " < 5.0.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04" | lts |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.0 Search vendor "Opensuse" for product "Leap" and version "15.0" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.1 Search vendor "Opensuse" for product "Leap" and version "15.1" | - |
Affected
|