Use-after-free in Linux kernel - CVE-2019-15211

 

Use-after-free in Linux kernel - CVE-2019-15211

Published: September 3, 2019


Vulnerability identifier: #VU20813
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15211
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists in the Raremono AM/FM/SW radio device driver in "drivers/media/v4l2-core/v4l2-dev.c" driver due to a use-after-free error when the "drivers/media/radio/radio-raremono.c" does not properly allocate memory. An authenticated local user with physical access to the system can use a malicious USB device to cause a denial of service or possibly execute arbitrary code.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Linux kernel
RSA Authentication Manager

How to mitigate CVE-2019-15211

Install updates from vendor's website.

Linux kernel - update to 5.2.6
RSA Authentication Manager - update to 8.4 Patch 9

External References

Related Security Bulletins