kernel: null-pointer dereference in hci_uart_set_flow_control
Published Nov 25, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.88%
Description
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
Affected products
-
- Version all versions kernel 3.x.x before 4.18.0 and kernel 5.x.xStatusaffectedConstraints-
- Version
- ≥ 3.0 · < 4.18.0
- ≥ 5.0 · ≤ 5.4
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.el7
Fixed · RHSA-2020:1016
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1127.rt56.1093.el7
Fixed · RHSA-2020:1070
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.rt24.93.el8
Fixed · RHSA-2019:3309
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.el7 | Fixed | RHSA-2020:1016 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1127.rt56.1093.el7 | Fixed | RHSA-2020:1070 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.rt24.93.el8 | Fixed | RHSA-2019:3309 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2019-10207 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1733874 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10207
- https://security.netapp.com/advisory/ntap-20200103-0001/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2019-10207
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-10207 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1733874 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10207 | ||
| https://security.netapp.com/advisory/ntap-20200103-0001/ | x_refsource_CONFIRM | |
| https://www.cve.org/CVERecord?id=CVE-2019-10207 |
Change history (0)
No recorded changes yet.