CVE-2019-3459

A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
References
Link Resource
http://www.openwall.com/lists/oss-security/2019/06/27/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/27/7 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/08/12/1 Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2029 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2043 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3309 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3517 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0740 Third Party Advisory
https://bugzilla.novell.com/show_bug.cgi?id=1120758 Issue Tracking Patch Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1663176 Issue Tracking Mitigation Third Party Advisory
https://git.kernel.org/linus/7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html Mailing List Third Party Advisory
https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047%40kroah.com/
https://marc.info/?l=oss-security&m=154721580222522&w=2 Exploit Mailing List Third Party Advisory
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3459.html Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/27/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/27/7 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/06/28/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/08/12/1 Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2029 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2043 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3309 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3517 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0740 Third Party Advisory
https://bugzilla.novell.com/show_bug.cgi?id=1120758 Issue Tracking Patch Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1663176 Issue Tracking Mitigation Third Party Advisory
https://git.kernel.org/linus/7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html Mailing List Third Party Advisory
https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047%40kroah.com/
https://marc.info/?l=oss-security&m=154721580222522&w=2 Exploit Mailing List Third Party Advisory
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3459.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time:7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2019/06/27/2 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2019/06/27/2 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2019/06/27/7 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2019/06/27/7 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2019/06/28/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2019/06/28/1 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2019/06/28/2 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2019/06/28/2 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2019/08/12/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2019/08/12/1 - Mailing List, Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2029 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2029 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2043 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2043 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:3309 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:3309 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:3517 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:3517 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0740 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0740 - Third Party Advisory
References () https://bugzilla.novell.com/show_bug.cgi?id=1120758 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.novell.com/show_bug.cgi?id=1120758 - Issue Tracking, Patch, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1663176 - Mitigation, Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1663176 - Issue Tracking, Mitigation, Third Party Advisory
References () https://git.kernel.org/linus/7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 - Patch, Vendor Advisory () https://git.kernel.org/linus/7c9cbd0b5e38a1672fcd137894ace3b042dfbf69 - Patch, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html - Mailing List, Third Party Advisory
References () https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047%40kroah.com/ - () https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047%40kroah.com/ -
References () https://marc.info/?l=oss-security&m=154721580222522&w=2 - Exploit, Mailing List, Third Party Advisory () https://marc.info/?l=oss-security&m=154721580222522&w=2 - Exploit, Mailing List, Third Party Advisory
References () https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3459.html - Third Party Advisory () https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3459.html - Third Party Advisory

07 Nov 2023, 03:09

Type Values Removed Values Added
References
  • {'url': 'https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047@kroah.com/', 'name': '[linux-bluetooth] 20190110 [PATCH 1/2] Bluetooth: check message types in l2cap_get_conf_opt', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'MLIST'}
  • () https://lore.kernel.org/linux-bluetooth/20190110062833.GA15047%40kroah.com/ -

Information

Published : 2019-04-11 16:29

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3459

Mitre link : CVE-2019-3459

CVE.ORG link : CVE-2019-3459


JSON object : View

Products Affected

redhat

  • enterprise_linux_server
  • enterprise_linux
  • enterprise_linux_for_real_time
  • enterprise_linux_desktop
  • codeready_linux_builder
  • enterprise_mrg
  • enterprise_linux_for_real_time_for_nfv
  • enterprise_linux_for_real_time_for_nfv_tus
  • enterprise_linux_server_aus
  • enterprise_linux_eus
  • enterprise_linux_for_real_time_tus
  • enterprise_linux_server_tus
  • enterprise_linux_workstation

canonical

  • ubuntu_linux

linux

  • linux_kernel

debian

  • debian_linux
CWE
CWE-125

Out-of-bounds Read