NULL pointer dereference in Linux kernel - CVE-2019-10207
Published: November 25, 2019 / Updated: June 1, 2020
Vulnerability details
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
Affected software
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Slackware Linux
Opensuse
Fedora
kernel-rt (Red Hat package)
kernel
kernel-headers
kernel-tools
How to mitigate CVE-2019-10207
kernel-rt (Red Hat package) - update to 4.18.0-147.rt24.93.el8
kernel - update to 5.2.5-200.fc30
kernel-headers - update to 5.2.5-200.fc30
kernel-tools - update to 5.2.5-200.fc30
External References
Related Security Bulletins
- NULL pointer dereference in Linux kernel
- OpenSUSE Linux update for SUSE Manager Client Tools
- OpenSUSE Linux update for the Linux Kernel
- OpenSUSE Linux update for the Linux Kernel
- Slackware Linux update for Slackware 14.2 kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Fedora 30 update for kernel, kernel-headers, kernel-tools