CVE Vulnerabilities

CVE-2019-12382

NULL Pointer Dereference

Published: May 28, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*5.1.5 (including)
Red Hat Enterprise Linux 7RedHatkernel-rt-0:3.10.0-1127.rt56.1093.el7*
Red Hat Enterprise Linux 7RedHatkernel-0:3.10.0-1127.el7*
Red Hat Enterprise Linux 7.7 Extended Update SupportRedHatkernel-0:3.10.0-1062.26.1.el7*
Red Hat Enterprise Linux 8RedHatkernel-0:4.18.0-147.el8*
LinuxUbuntubionic*
LinuxUbuntucosmic*
LinuxUbuntudisco*
LinuxUbuntuesm-infra-legacy/trusty*
LinuxUbuntuprecise/esm*
LinuxUbuntutrusty*
LinuxUbuntutrusty/esm*
LinuxUbuntuxenial*
Linux-awsUbuntubionic*
Linux-awsUbuntucosmic*
Linux-awsUbuntudisco*
Linux-awsUbuntuesm-infra-legacy/trusty*
Linux-awsUbuntutrusty*
Linux-awsUbuntutrusty/esm*
Linux-awsUbuntuxenial*
Linux-aws-hweUbuntuxenial*
Linux-azureUbuntubionic*
Linux-azureUbuntucosmic*
Linux-azureUbuntudisco*
Linux-azureUbuntuesm-infra-legacy/trusty*
Linux-azureUbuntutrusty*
Linux-azureUbuntutrusty/esm*
Linux-azureUbuntuxenial*
Linux-azure-edgeUbuntubionic*
Linux-azure-edgeUbuntuxenial*
Linux-euclidUbuntuxenial*
Linux-floUbuntutrusty*
Linux-floUbuntuxenial*
Linux-gcpUbuntubionic*
Linux-gcpUbuntucosmic*
Linux-gcpUbuntudisco*
Linux-gcpUbuntuxenial*
Linux-gcp-edgeUbuntubionic*
Linux-gkeUbuntubionic*
Linux-gkeUbuntuxenial*
Linux-goldfishUbuntutrusty*
Linux-goldfishUbuntuxenial*
Linux-grouperUbuntutrusty*
Linux-hweUbuntubionic*
Linux-hweUbuntuxenial*
Linux-hwe-edgeUbuntubionic*
Linux-hwe-edgeUbuntuxenial*
Linux-kvmUbuntubionic*
Linux-kvmUbuntucosmic*
Linux-kvmUbuntudisco*
Linux-kvmUbuntuxenial*
Linux-lts-trustyUbuntuprecise/esm*
Linux-lts-utopicUbuntutrusty*
Linux-lts-vividUbuntutrusty*
Linux-lts-wilyUbuntutrusty*
Linux-lts-xenialUbuntuesm-infra-legacy/trusty*
Linux-lts-xenialUbuntutrusty*
Linux-lts-xenialUbuntutrusty/esm*
Linux-maguroUbuntutrusty*
Linux-makoUbuntutrusty*
Linux-makoUbuntuxenial*
Linux-mantaUbuntutrusty*
Linux-oemUbuntubionic*
Linux-oemUbuntucosmic*
Linux-oemUbuntudisco*
Linux-oemUbuntuxenial*
Linux-oracleUbuntubionic*
Linux-oracleUbuntucosmic*
Linux-oracleUbuntudisco*
Linux-oracleUbuntuxenial*
Linux-raspi2Ubuntubionic*
Linux-raspi2Ubuntucosmic*
Linux-raspi2Ubuntudisco*
Linux-raspi2Ubuntuxenial*
Linux-snapdragonUbuntubionic*
Linux-snapdragonUbuntudisco*
Linux-snapdragonUbuntuxenial*

Potential Mitigations

References