CVE Vulnerabilities

CVE-2019-12456

Published: May 30, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of ioc_number between two kernel reads of that value, aka a double fetch vulnerability. NOTE: a third party reports that this is unexploitable because the doubly fetched value is not used

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*5.1.5 (including)
LinuxUbuntubionic*
LinuxUbuntucosmic*
LinuxUbuntudisco*
LinuxUbuntuesm-infra-legacy/trusty*
LinuxUbuntuprecise/esm*
LinuxUbuntutrusty*
LinuxUbuntutrusty/esm*
LinuxUbuntuxenial*
Linux-awsUbuntubionic*
Linux-awsUbuntucosmic*
Linux-awsUbuntudisco*
Linux-awsUbuntuesm-infra-legacy/trusty*
Linux-awsUbuntutrusty*
Linux-awsUbuntutrusty/esm*
Linux-awsUbuntuxenial*
Linux-aws-hweUbuntuxenial*
Linux-azureUbuntubionic*
Linux-azureUbuntucosmic*
Linux-azureUbuntudisco*
Linux-azureUbuntuesm-infra-legacy/trusty*
Linux-azureUbuntutrusty*
Linux-azureUbuntutrusty/esm*
Linux-azureUbuntuxenial*
Linux-azure-edgeUbuntubionic*
Linux-azure-edgeUbuntuxenial*
Linux-euclidUbuntuxenial*
Linux-floUbuntutrusty*
Linux-floUbuntuxenial*
Linux-gcpUbuntubionic*
Linux-gcpUbuntucosmic*
Linux-gcpUbuntudisco*
Linux-gcpUbuntuxenial*
Linux-gcp-edgeUbuntubionic*
Linux-gkeUbuntubionic*
Linux-gkeUbuntuxenial*
Linux-goldfishUbuntutrusty*
Linux-goldfishUbuntuxenial*
Linux-grouperUbuntutrusty*
Linux-hweUbuntubionic*
Linux-hweUbuntuxenial*
Linux-hwe-edgeUbuntubionic*
Linux-hwe-edgeUbuntuxenial*
Linux-kvmUbuntubionic*
Linux-kvmUbuntucosmic*
Linux-kvmUbuntudisco*
Linux-kvmUbuntuxenial*
Linux-lts-trustyUbuntuprecise/esm*
Linux-lts-utopicUbuntutrusty*
Linux-lts-vividUbuntutrusty*
Linux-lts-wilyUbuntutrusty*
Linux-lts-xenialUbuntuesm-infra-legacy/trusty*
Linux-lts-xenialUbuntutrusty*
Linux-lts-xenialUbuntutrusty/esm*
Linux-maguroUbuntutrusty*
Linux-makoUbuntutrusty*
Linux-makoUbuntuxenial*
Linux-mantaUbuntutrusty*
Linux-oemUbuntubionic*
Linux-oemUbuntucosmic*
Linux-oemUbuntudisco*
Linux-oemUbuntuxenial*
Linux-oracleUbuntubionic*
Linux-oracleUbuntucosmic*
Linux-oracleUbuntudisco*
Linux-oracleUbuntuxenial*
Linux-raspi2Ubuntubionic*
Linux-raspi2Ubuntucosmic*
Linux-raspi2Ubuntudisco*
Linux-raspi2Ubuntuxenial*
Linux-snapdragonUbuntubionic*
Linux-snapdragonUbuntudisco*
Linux-snapdragonUbuntuxenial*

References