CVE-2019-10207
Vulnerability Summary
Timeline
Description
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- v3.0•MEDIUM•Score: 4.7CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.88%• Percentile: 58%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- debian•linux
< 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1
- ubuntu•linux
all | < 4.4.0-165.193 | < 4.15.0-60.67
- ubuntu•linux-aws
< 4.4.0-1055.59 | < 4.4.0-1095.106 | < 4.15.0-1047.49
- ubuntu•linux-aws-fips
< 4.15.0-2018.18 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1047.49~16.04.1
- ubuntu•linux-azure
< 4.15.0-1059.64~14.04.1
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1022.27 | all
- ubuntu•linux-gcp
< 4.15.0-1041.43 | < 4.15.0-1042.45
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke-4.15
< 4.15.0-1041.43
- ubuntu•linux-gke-5.0
< 5.0.0-1020.20~18.04.1
- ubuntu•linux-hwe
< 4.15.0-60.67~16.04.1 | < 5.0.0-31.33~18.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1059.66 | < 4.15.0-1043.43
- ubuntu•linux-lts-xenial
< 4.4.0-165.193~14.04.1
- ubuntu•linux-oem
< 4.15.0-1056.65
- ubuntu•linux-oem-osp1
< 5.0.0-1024.27
- ubuntu•linux-oracle
< 4.15.0-1022.25~16.04.1 | < 4.15.0-1022.25
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1123.132 | < 4.15.0-1044.47
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1127.135 | < 4.15.0-1062.69
- linux•linux_kernel
≥ 3.0, < 4.18.0 | ≥ 5.0, ≤ 5.4
- red hat•kernel
all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x
References (11)
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207
- https://security.netapp.com/advisory/ntap-20200103-0001/
- https://ubuntu.com/security/CVE-2019-10207
- https://www.openwall.com/lists/oss-security/2019/07/25/1
- https://lore.kernel.org/linux-bluetooth/20190729122215.9948-1-vdronov@redhat.com/
- https://ubuntu.com/security/notices/USN-4115-1
- https://ubuntu.com/security/notices/USN-4118-1
- https://ubuntu.com/security/notices/USN-4145-1
- https://ubuntu.com/security/notices/USN-4147-1
- https://www.cve.org/CVERecord?id=CVE-2019-10207
- https://security-tracker.debian.org/tracker/CVE-2019-10207