kernel: out-of-bounds in function build_audio_procunit in sound/usb/mixer.c
Published Sep 4, 2019
7.8
HIGHCVSS 3.1
EPSS 0.41%
Description
An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the function build_audio_procunit in the file sound/usb/mixer.c.
Affected products
No data.
- < 3.16.66
- ≥ 3.17 · < 3.18.132
- ≥ 3.19 · < 4.4.170
- ≥ 4.5 · < 4.9.150
- ≥ 4.10 · < 4.14.93
- ≥ 4.15 · < 4.19.15
- ≥ 4.20 · < 4.20.2
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.el7
Fixed · RHSA-2019:2029
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.el8
Fixed · RHSA-2019:3517
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise MRG 2
kernel
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.el7 | Fixed | RHSA-2019:2029 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.el8 | Fixed | RHSA-2019:3517 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-15927 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1759059 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20.2 x_refsource_MISCMailing ListVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6831 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f4351a199cc120ff9d59e06d02e8657d08e6cc46 x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15927
- https://security.netapp.com/advisory/ntap-20191004-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15927
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-15927 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1759059 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.20.2 | x_refsource_MISCMailing ListVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6831 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f4351a199cc120ff9d59e06d02e8657d08e6cc46 | x_refsource_MISCMailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15927 | ||
| https://security.netapp.com/advisory/ntap-20191004-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-15927 |
Change history (0)
No recorded changes yet.