CVE-2019-11810

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 7.8 (High)
78% Progress
EPSS 1.82 % (89th)
1.82% Progress
Affected Products 3
Advisories 29

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-free.

Weaknesses
CWE-416
Use After Free
CWE-476
NULL Pointer Dereference
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-05-07 14:29:00
(5 years ago)
Updated Date
2022-12-02 19:46:50
(21 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 3.16.69 version cpe:2.3:o:linux:linux_kernel < 3.16.69
  Linux Kernel from 3.17 version and prior 3.18.139 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.139
  Linux Kernel from 3.19 version and prior 4.4.179 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 4.4.179
  Linux Kernel from 4.5 version and prior 4.9.168 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.168
  Linux Kernel from 4.10 version and prior 4.14.111 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.111
  Linux Kernel from 4.15 version and prior 4.19.34 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.34
  Linux Kernel from 4.20 version and prior 5.0.7 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.0.7

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts
  Canonical Ubuntu Linux 19.04 cpe:2.3:o:canonical:ubuntu_linux:19.04

Configuration #3

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...