kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c
Published Sep 11, 2019
4.1
MEDIUMCVSS 3.1
EPSS 0.38%
Description
drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
Affected products
No data.
Configuration 1
- 5.2.14
Configuration 2
- 14.04
- 16.04
- 18.04
- 19.04
- 15.0
- 15.1
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.el7
Fixed · RHSA-2020:4060
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.rt56.1131.el7
Fixed · RHSA-2020:4062
Red Hat Enterprise Linux 8
kernel-0:4.18.0-240.el8
Fixed · RHSA-2020:4431
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-240.rt7.54.el8
Fixed · RHSA-2020:4609
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Fix deferred
Red Hat Enterprise MRG 2
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.el7 | Fixed | RHSA-2020:4060 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.rt56.1131.el7 | Fixed | RHSA-2020:4062 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-240.el8 | Fixed | RHSA-2020:4431 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-240.rt7.54.el8 | Fixed | RHSA-2020:4609 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Fix deferred | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-16233 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760420 Issue Tracking
- https://lkml.org/lkml/2019/9/9/487 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-16233
- https://security.netapp.com/advisory/ntap-20191004-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4226-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4227-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4227-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4346-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-16233
Change history (0)
No recorded changes yet.