NULL pointer dereference in Linux kernel and Cisco Unified Contact Center Enterprise - CVE-2019-15098
Published: September 6, 2019 / Updated: May 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the "drivers/net/wireless/ath/ath6kl/usb.c". A remote attacker can trigger denial of service conditions via an incomplete address in an endpoint descriptor.
Affected software
Slackware Linux
Cisco Unified Contact Center Enterprise
linux-4.4.199/kernel-generic
linux-4.4.199/kernel-huge
linux-4.4.199/kernel-modules
linux-4.4.199/kernel-headers
How to mitigate CVE-2019-15098
linux-4.4.199/kernel-generic - update to 4.4.199
linux-4.4.199/kernel-huge - update to 4.4.199
linux-4.4.199/kernel-modules - update to 4.4.199
linux-4.4.199/kernel-headers - update to 4.4.199_smp
External References
- https://lore.kernel.org/linux-wireless/20190804002905.11292-1-benquike@gmail.com/T/#u
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.82
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.152
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.199
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.199
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9