{"id":"CVE-2019-15218","title":"An issue was discovered in the Linux kernel before 5.1.8","summary":"An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver.","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"netapp","product":"active_iq_unified_manager","affected":["linux_kernel < 5.1.8","h410c_firmware","active_iq_unified_manager","data_availability_services","solidfire_&_hci_management_node","solidfire_baseboard_management_controller","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 19.04","debian_linux = 8.0","sd-wan_edge = 8.2","leap = 15.0","leap = 15.1"],"patched":["linux_kernel 5.1.8"],"published":"2019-08-19","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:14.907","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-15218","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/20/2","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/2","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/3","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/4","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/5","label":"cve@mitre.org"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.8","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=31e0456de5be379b10fea0fa94a681057114a96e","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20190905-0002/","label":"cve@mitre.org"},{"url":"https://syzkaller.appspot.com/bug?id=4a5d7c8c2b6dbedb5b7218c6d7e8666bd2387517","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4115-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4118-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4147-1/","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/20/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2019/08/22/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.8","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=31e0456de5be379b10fea0fa94a681057114a96e","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20190905-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://syzkaller.appspot.com/bug?id=4a5d7c8c2b6dbedb5b7218c6d7e8666bd2387517","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4115-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4118-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4147-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00839,"epssPercentile":0.56506,"ingestedAt":"2026-10-08T22:11:53.700Z","slug":"CVE-2019-15218","body":"## Overview\n\nAn issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver.\n\n## Affected\n\n- `linux_kernel < 5.1.8`\n- `h410c_firmware`\n- `active_iq_unified_manager`\n- `data_availability_services`\n- `solidfire_&_hci_management_node`\n- `solidfire_baseboard_management_controller`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 19.04`\n- `debian_linux = 8.0`\n- `sd-wan_edge = 8.2`\n- `leap = 15.0`\n- `leap = 15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.1.8`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}