Bug 1149609 - (CVE-2019-15923) VUL-1: CVE-2019-15923: kernel-source: NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c
(CVE-2019-15923)
VUL-1: CVE-2019-15923: kernel-source: NULL pointer dereference for a cd data ...
Status: RESOLVED INVALID
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P5 - None : Minor (vote)
: ---
Assigned To: E-mail List
Security Team bot
https://smash.suse.de/issue/241760/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-09-05 12:56 UTC by Alexandros Toptsoglou
Modified: 2019-09-05 12:57 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-09-05 12:56:36 UTC
CVE-2019-15923

An issue was discovered in the Linux kernel before 5.0.9. There is a NULL
pointer dereference for a cd data structure if alloc_disk fails in
drivers/block/paride/pf.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15923
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15923
https://github.com/torvalds/linux/commit/f0d1762554014ce0ae347b9f0d088f2c157c8c72
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.9
Comment 1 Alexandros Toptsoglou 2019-09-05 12:57:42 UTC
The issue introduced in [1] (version 5.1rc2) and fixed in [2] (version 5.1rc4) 
No internal branch is affected and Factory is already fixed.

[1]https://github.com/torvalds/linux/commit/6ce59025f1182125e75c8d121daf44056b65dd1f
[2]
https://github.com/torvalds/linux/commit/f0d1762554014ce0ae347b9f0d088f2c157c8c72