9.8

CVE-2019-10126

A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.2 < 4.4.186
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.186
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.134
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.59
Linux ≫ Linux Kernel Version >= 4.20 < 5.1.18
Redhat ≫ Virtualization Version 4.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Aus Version 8.2
Redhat ≫ Enterprise Linux Aus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Netapp ≫ Active Iq Unified Manager SwPlatform vmware_vsphere Version >= 9.5
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ A700s Firmware Version -
   Netapp ≫ A700s Version -
Netapp ≫ Cn1610 Firmware Version -
   Netapp ≫ Cn1610 Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.82% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/errata/RHSA-2019:3517
Third Party Advisory
https://usn.ubuntu.com/4094-1/
Third Party Advisory
https://usn.ubuntu.com/4118-1/
Third Party Advisory
http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2020:0174
Third Party Advisory
https://usn.ubuntu.com/4095-1/
Third Party Advisory
https://usn.ubuntu.com/4095-2/
Third Party Advisory
http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
Patch
Third Party Advisory
VDB Entry
https://seclists.org/bugtraq/2019/Jul/33
Patch
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:3309
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0204
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/06/msg00010.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Jun/26
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4465
Third Party Advisory
https://usn.ubuntu.com/4117-1/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00014.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00025.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
Third Party Advisory
VDB Entry
https://security.netapp.com/advisory/ntap-20190710-0002/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3055
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3076
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3089
Third Party Advisory
https://usn.ubuntu.com/4093-1/
Third Party Advisory
http://www.securityfocus.com/bid/108817
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10126
Patch
Third Party Advisory
Issue Tracking
https://support.f5.com/csp/article/K95593121
Third Party Advisory