imPC@ndo IT

Tracker / CVE-2019-25162

CVE-2019-25162

High 7.8

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after free. [wsa: added comment to the code, added Fixes tag]

Affected products and versions

linux linux_kernel · 4.15.0 → 4.19.256
linux linux_kernel · 4.20.0 → 5.4.211
linux linux_kernel · 4.3.0 → 4.14.291
linux linux_kernel · 5.11.0 → 5.15.61
linux linux_kernel · 5.16.0 → 5.18.18
linux linux_kernel · 5.19.0 → 5.19.2
linux linux_kernel · 5.5.0 → 5.10.137

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References