kernel: null pointer dereference in drivers/net/ethernet/intel/fm10k/fm10k_main.c
Published Sep 4, 2019
5.5
MEDIUMCVSS 3.0
EPSS 0.52%
Description
An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference because there is no -ENOMEM upon an alloc_workqueue failure.
Affected products
No data.
- < 5.0.11
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.rt24.93.el8
Fixed · RHSA-2019:3309
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.rt24.93.el8 | Fixed | RHSA-2019:3309 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is rated as having Low impact because of the low memory conditions needed to trigger this issue.
Red Hat mitigation
To mitigate this issue, prevent module fm10k from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-15924 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1763869 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.11 x_refsource_MISCMailing ListVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6828 Advisory
- https://github.com/torvalds/linux/commit/01ca667133d019edc9f0a1f70a272447c84ec41f x_refsource_MISCExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-15924
- https://security.netapp.com/advisory/ntap-20191004-0001/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2019-15924
Change history (0)
No recorded changes yet.