Use-after-free in Linux kernel - CVE-2019-15215

 

Use-after-free in Linux kernel - CVE-2019-15215

Published: September 3, 2019


Vulnerability identifier: #VU20816
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15215
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the CPiA2 video4linux device driver in the "drivers/media/usb/cpia2/cpia2_usb.c" driver. A local authenticated user with physical access to the system can use a malicious USB device and cause a denial of service (system crash) or possibly execute arbitrary code.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Linux kernel
RSA Authentication Manager

How to mitigate CVE-2019-15215

Install updates from vendor's website.

Linux kernel - update to 5.2.6
RSA Authentication Manager - update to 8.4 Patch 9

External References

Related Security Bulletins