CVE-2019-15217 PUBLISHED

An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.

EPSS 0.06% · 19.7th percentile

Risk Scores

EPSS Score
0.06%
19.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1058.64, 4.15.0-1057.62, 4.15.0-1055.59
Ubuntu:18.04:LTSlinux-kvm4.15.0-1025.25, 4.15.0-1026.26, 4.15.0-1027.27
Ubuntu:16.04:LTSlinux-gcp4.15.0-1027.28~16.04.1, 4.15.0-1026.27~16.04.1, 4.15.0-1025.26~16.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips0, 4.15.0-1002.2
Ubuntu:18.04:LTSlinux-gcp4.15.0-1024.25, 4.15.0-1025.26, 4.15.0-1026.27
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips0, 4.15.0-1001.1
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1054.56~16.04.1, 4.15.0-1056.58~16.04.1, 4.15.0-1057.59~16.04.1
Ubuntu:18.04:LTSlinux-aws4.15.0-1044.46, 4.15.0-1043.45, 4.15.0-1041.43
Ubuntu:Pro:14.04:LTSlinux3.13.0-53.89, 0, 3.11.0-12.19
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1013.15, 4.4.0-1058.62, 4.4.0-1059.63
Ubuntu:18.04:LTSlinux-oem4.15.0-1050.57, 4.15.0-1002.3, 4.15.0-1004.5
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-24.28, 5.4.0-26.30
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1048.51, 4.15.0-1049.52, 4.15.0-1050.53
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1056.61~14.04.1, 4.15.0-1071.76~14.04.1, 4.15.0-1069.74~14.04.1
Ubuntu:18.04:LTSlinux4.15.0-64.73, 4.15.0-62.69, 4.15.0-60.67
Ubuntu:16.04:LTSlinux-azure4.15.0-1049.54, 0, 4.11.0-1009.9
Ubuntu:16.04:LTSlinux-hwe-edge4.10.0-21.23~16.04.1, 4.10.0-24.28~16.04.1, 4.10.0-26.30~16.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-aws-fips0, 4.15.0-2000.4
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips0, 4.15.0-1002.2

…and 22 more

Timeline

References

Open in Interactive Console →