Executive Summary

Informations
NameCVE-2019-12456First vendor Publication2019-05-30
VendorCveLast vendor Modification2019-06-20

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score7.2Attack RangeLocal
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score3.9AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

** DISPUTED ** An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of ioc_number between two kernel reads of that value, aka a "double fetch" vulnerability. NOTE: a third party reports that this is unexploitable because the doubly fetched value is not used.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12456

CWE : Common Weakness Enumeration

%idName
100 %CWE-20Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Os3243

Sources (Detail)

SourceUrl
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedorapr...
MISC https://bugzilla.redhat.com/show_bug.cgi?id=1717182
https://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi.git/commit/?h=5.3/sc...
https://lkml.org/lkml/2019/5/29/1164
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
DateInformations
2019-07-02 15:40:04
  • Multiple Updates
2019-06-21 00:19:17
  • Multiple Updates
2019-06-20 17:19:20
  • Multiple Updates
2019-06-19 09:19:33
  • Multiple Updates
2019-06-19 00:19:33
  • Multiple Updates
2019-06-18 21:19:27
  • Multiple Updates
2019-06-17 17:19:05
  • Multiple Updates
2019-06-15 12:10:36
  • Multiple Updates
2019-06-14 21:19:43
  • Multiple Updates
2019-06-13 09:20:21
  • Multiple Updates
2019-06-12 21:19:22
  • Multiple Updates
2019-05-31 12:09:43
  • Multiple Updates
2019-05-30 21:19:29
  • First insertion