CVE-2019-12382 PUBLISHED

An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference

EPSS 0.12% · 30.6th percentile

Risk Scores

EPSS Score
0.12%
30.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-aws0, 4.4.0-1002.2, 4.4.0-1003.3
Ubuntu:Pro:14.04:LTSlinux3.13.0-125.174, 3.13.0-126.175, 3.13.0-128.177
Ubuntu:Pro:14.04:LTSlinux-azure0, 4.15.0-1023.24~14.04.1, 4.15.0-1030.31~14.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial0, 4.4.0-13.29~14.04.1, 4.4.0-14.30~14.04.2

Timeline

References

Open in Interactive Console →