VDB

CVE-2019-12382

CVE-2019-12382 PUBLISHED

An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference

EPSS 0.11% · 29.6th percentile

Risk Scores

EPSS Score
0.11%
29.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1044.47, 4.4.0-1045.48, 4.4.0-1048.52
Ubuntu:Pro:14.04:LTSlinux3.13.0-77.121, 3.13.0-76.120, 3.13.0-71.114
Ubuntu:Pro:14.04:LTSlinux-azure*, 0, 4.15.0-1023.24~14.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-127.153~14.04.1, 4.4.0-124.148~14.04.1, 4.4.0-121.145~14.04.1

Timeline

  • May 28, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›