NULL pointer dereference in Linux kernel - CVE-2019-15291
Published: September 6, 2019
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the "flexcop_usb_probe" function in the "drivers/media/usb/b2c2/flexcop-usb.c" driver. A local attacker with physical access can use a malicious USB device and perform a denial of service (DoS) attack.
Affected software
Slackware Linux
Opensuse
RSA Authentication Manager
How to mitigate CVE-2019-15291
RSA Authentication Manager - update to 8.4 Patch 9