VulnerabilityModified
CVE-2019-10207
An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
MEDIUM 5.5EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200103-0001/
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200103-0001/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.