NULL pointer dereference in Linux kernel - CVE-2019-10207

 

NULL pointer dereference in Linux kernel - CVE-2019-10207

Published: November 25, 2019 / Updated: June 1, 2020


Vulnerability identifier: #VU28401
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10207
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Slackware Linux
Opensuse
Fedora
kernel-rt (Red Hat package)
kernel
kernel-headers
kernel-tools

How to mitigate CVE-2019-10207

Install update from vendor's website.

Linux kernel - addressed in versions 4.14.136, 5.3
kernel-rt (Red Hat package) - update to 4.18.0-147.rt24.93.el8
kernel - update to 5.2.5-200.fc30
kernel-headers - update to 5.2.5-200.fc30
kernel-tools - update to 5.2.5-200.fc30

External References

Related Security Bulletins