Vulnerability Name: | CVE-2019-12454 (CCN-161815) | ||||||||||||||||
Assigned: | 2019-05-29 | ||||||||||||||||
Published: | 2019-05-29 | ||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||
Summary: | ** DISPUTED ** An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses kstrndup instead of kmemdup_nul, which allows attackers to have an unspecified impact via unknown vectors. Note: The vendor disputes this issues as not being a vulnerability because switching to kmemdup_nul() would only fix a security issue if the source string wasn't NUL-terminated, which is not the case. | ||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-12454 Source: MISC Type: UNKNOWN https://bugzilla.suse.com/show_bug.cgi?id=1136963#c1 Source: XF Type: UNKNOWN linux-kernel-cve201912454-unspecified(161815) Source: CCN Type: Linux Kernel GIT Repository wcd9335: fix a incorrect use of kstrndup() Source: MISC Type: Mailing List, Patch, Vendor Advisory https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git/commit/?h=for-5.3&id=a54988113985ca22e414e132054f234fc8a92604 Source: FEDORA Type: UNKNOWN FEDORA-2019-f40bd7826f Source: MISC Type: Mailing List, Patch, Third Party Advisory https://lkml.org/lkml/2019/5/29/705 Source: CONFIRM Type: UNKNOWN https://support.f5.com/csp/article/K13523672 Source: CONFIRM Type: UNKNOWN https://support.f5.com/csp/article/K13523672?utm_source=f5support&utm_medium=RSS | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |