kernel: use-after-free in function __mdiobus_register() in drivers/net/phy/mdio_bus.c
Published Jun 14, 2019
5.5
MEDIUMCVSS 3.0
EPSS 0.64%
Description
An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which will trigger a fixed_mdio_bus_init use-after-free. This will cause a denial of service.
Affected products
No data.
- < 5.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-193.el8
Fixed · RHSA-2020:1769
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-193.rt13.51.el8
Fixed · RHSA-2020:1567
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-193.el8 | Fixed | RHSA-2020:1769 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-193.rt13.51.el8 | Fixed | RHSA-2020:1567 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html vendor-advisoryx_refsource_SUSE
- http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html x_refsource_MISC
- http://www.securityfocus.com/bid/108768 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-12819 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1721962 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4400 Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6ff7b060535e87c2ae14dd8548512abfdda528fb x_refsource_MISCMailing ListPatchVendor Advisory
- https://github.com/torvalds/linux/commit/6ff7b060535e87c2ae14dd8548512abfdda528fb x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-12819
- https://security.netapp.com/advisory/ntap-20190710-0002/ x_refsource_CONFIRM
- https://usn.ubuntu.com/4094-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4118-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-12819
Change history (0)
No recorded changes yet.