CVE-2019-15218Medium· 4.6▾ SunlitAn issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver.
linux_kernel < 5.1.8h410c_firmwareactive_iq_unified_managerdata_availability_servicessolidfire_&_hci_management_nodesolidfire_baseboard_management_controllerubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 19.04debian_linux = 8.0sd-wan_edge = 8.2leap = 15.0leap = 15.1Upgrade past the affected range:
linux_kernel 5.1.8Connected by shared product, vendor, weakness, or advisory.
CVE-2019-15219Medium· 4.6An issue was discovered in the Linux kernel before 5.1.8
CVE-2019-15217Medium· 4.6An issue was discovered in the Linux kernel before 5.2.3
CVE-2019-19965Medium· 4.7In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-19462Medium· 5.5relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
CVE-2021-21345Medium· 5.8XStream is a Java library to serialize objects to XML and back again
CVE-2022-1199High· 7.5A flaw was found in the Linux kernel