An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5d2e73a5f80a5b5aff3caf1ec6d39b5b3f54b26e",
"id": "CVE-2019-15217-86c55b3d",
"target": {
"file": "drivers/media/usb/zr364xx/zr364xx.c",
"function": "zr364xx_vidioc_querycap"
},
"digest": {
"function_hash": "156875930741905010265030303776686256522",
"length": 536.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5d2e73a5f80a5b5aff3caf1ec6d39b5b3f54b26e",
"id": "CVE-2019-15217-c135c5a5",
"target": {
"file": "drivers/media/usb/zr364xx/zr364xx.c"
},
"digest": {
"line_hashes": [
"174524742174181400388060485427390998692",
"251660787761215587393012886910073234680",
"322300282364319974327220619732213203963",
"88693675209294884983000177763919390458"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15217.json"