Bugzilla – Bug 1149609
VUL-1: CVE-2019-15923: kernel-source: NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c
Last modified: 2019-09-05 12:57:42 UTC
CVE-2019-15923 An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15923 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15923 https://github.com/torvalds/linux/commit/f0d1762554014ce0ae347b9f0d088f2c157c8c72 https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.9
The issue introduced in [1] (version 5.1rc2) and fixed in [2] (version 5.1rc4) No internal branch is affected and Factory is already fixed. [1]https://github.com/torvalds/linux/commit/6ce59025f1182125e75c8d121daf44056b65dd1f [2] https://github.com/torvalds/linux/commit/f0d1762554014ce0ae347b9f0d088f2c157c8c72