{"id":"CVE-2019-15217","title":"An issue was discovered in the Linux kernel before 5.2.3","summary":"An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"netapp","product":"active_iq_unified_manager","affected":["linux_kernel < 5.2.3","h410c_firmware","active_iq_unified_manager","data_availability_services","solidfire_&_hci_management_node","solidfire_baseboard_management_controller","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 19.04","debian_linux = 8.0","leap = 15.0","leap = 15.1"],"patched":["linux_kernel 5.2.3"],"published":"2019-08-19","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:14.607","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-15217","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/20/2","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/2","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/3","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/4","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/5","label":"cve@mitre.org"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5d2e73a5f80a5b5aff3caf1ec6d39b5b3f54b26e","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20190905-0002/","label":"cve@mitre.org"},{"url":"https://syzkaller.appspot.com/bug?id=9c0c178c24d828a7378f483309001329750aad64","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4147-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4286-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4286-2/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4302-1/","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/20/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5d2e73a5f80a5b5aff3caf1ec6d39b5b3f54b26e","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20190905-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://syzkaller.appspot.com/bug?id=9c0c178c24d828a7378f483309001329750aad64","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4147-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4286-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4286-2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4302-1/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0068,"epssPercentile":0.5087,"ingestedAt":"2026-10-08T22:11:53.699Z","slug":"CVE-2019-15217","body":"## Overview\n\nAn issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.\n\n## Affected\n\n- `linux_kernel < 5.2.3`\n- `h410c_firmware`\n- `active_iq_unified_manager`\n- `data_availability_services`\n- `solidfire_&_hci_management_node`\n- `solidfire_baseboard_management_controller`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 19.04`\n- `debian_linux = 8.0`\n- `leap = 15.0`\n- `leap = 15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.2.3`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}