kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg
Published Sep 4, 2019
7.8
HIGHCVSS 3.1
EPSS 0.35%
Description
An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
Affected products
No data.
Configuration 1
- ≥ 4.14 · < 4.14.135
- ≥ 4.15 · < 4.19.61
- ≥ 4.20 · < 5.1.20
- ≥ 5.2 · < 5.2.3
Configuration 2
- 18.04
- 19.04
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-240.el8
Fixed · RHSA-2020:4431
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-240.rt7.54.el8
Fixed · RHSA-2020:4609
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-240.el8 | Fixed | RHSA-2020:4431 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-240.rt7.54.el8 | Fixed | RHSA-2020:4609 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Blacklisting the affected HCLGE driver module until a patch is available can be done using the blacklist mechanism. This will ensure the driver is not loaded at boot time. For instructions on how to black list a kernel module, please read: https://access.redhat.com/solutions/41278.
References (8)
- https://access.redhat.com/security/cve/CVE-2019-15925 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1759052 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3 x_refsource_MISCMailing ListVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04f25edb48c441fc278ecc154c270f16966cbb90 x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15925
- https://security.netapp.com/advisory/ntap-20191004-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4147-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15925
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-15925 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1759052 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3 | x_refsource_MISCMailing ListVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04f25edb48c441fc278ecc154c270f16966cbb90 | x_refsource_MISCMailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15925 | ||
| https://security.netapp.com/advisory/ntap-20191004-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://usn.ubuntu.com/4147-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-15925 |
Change history (0)
No recorded changes yet.