An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15216.json"
[
{
"id": "CVE-2019-15216-2207182e",
"target": {
"file": "drivers/usb/misc/yurex.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@ef61eb43ada6c1d6b94668f0f514e4c268093ff3",
"digest": {
"threshold": 0.9,
"line_hashes": [
"142695964972805167075415357746960872020",
"264600341252245262811787396402242158904",
"203155377007670938162003635855581572462"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2019-15216-db89d6cc",
"target": {
"function": "yurex_disconnect",
"file": "drivers/usb/misc/yurex.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@ef61eb43ada6c1d6b94668f0f514e4c268093ff3",
"digest": {
"function_hash": "72305878033979905800903748688805499006",
"length": 465.0
},
"signature_type": "Function"
}
]