Vulnerability Description
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.0, < 4.18.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200103-0001/
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10207Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200103-0001/
FAQ
What is CVE-2019-10207?
CVE-2019-10207 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth ...
How severe is CVE-2019-10207?
CVE-2019-10207 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10207?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.