Oval Definition:oval:com.ubuntu.xenial:def:2019162300000000
Revision Date:2019-09-11Version:1
Title:CVE-2019-16230 on Ubuntu 16.04 LTS (xenial) - low.
Description:** DISPUTED ** drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics card occurs during boot. It is not attacker controllable and OOM at that time is highly unlikely. It was discovered that the Radeon Linux kernel driver for AMD GPU devices did not properly check for errors in certain situations, leading to a NULL pointer dereference. A local attacker could possibly use this to cause a denial of service.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-16230
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • linux package in xenial is affected and needs fixing.
  • OR linux-aws package in xenial is affected and needs fixing.
  • OR linux-aws-hwe package in xenial is affected and needs fixing.
  • OR linux-azure package in xenial is affected and needs fixing.
  • OR linux-gcp package in xenial is affected and needs fixing.
  • OR linux-hwe package in xenial is affected and needs fixing.
  • OR linux-kvm package in xenial is affected and needs fixing.
  • OR linux-meta package in xenial is affected and needs fixing.
  • OR linux-meta-aws package in xenial is affected and needs fixing.
  • OR linux-meta-aws-hwe package in xenial is affected and needs fixing.
  • OR linux-meta-azure package in xenial is affected and needs fixing.
  • OR linux-meta-gcp package in xenial is affected and needs fixing.
  • OR linux-meta-hwe package in xenial is affected and needs fixing.
  • OR linux-meta-kvm package in xenial is affected and needs fixing.
  • OR linux-meta-oracle package in xenial is affected and needs fixing.
  • OR linux-meta-raspi2 package in xenial is affected and needs fixing.
  • OR linux-meta-snapdragon package in xenial is affected and needs fixing.
  • OR linux-oem: while related to the CVE in some way, a decision has been made to ignore this issue (note: 'was needs-triage now end-of-life').
  • OR linux-oracle package in xenial is affected and needs fixing.
  • OR linux-raspi2 package in xenial is affected and needs fixing.
  • OR linux-signed package in xenial is affected and needs fixing.
  • OR linux-signed-azure package in xenial is affected and needs fixing.
  • OR linux-signed-gcp package in xenial is affected and needs fixing.
  • OR linux-signed-hwe package in xenial is affected and needs fixing.
  • OR linux-signed-oracle package in xenial is affected and needs fixing.
  • OR linux-snapdragon package in xenial is affected and needs fixing.
  • BACK