peter bassill · operator
$ cve CVE-2019-10126 JSON

CVE-2019-10126

9.8
CRITICAL · CVSS 3.1 · EPSS 6.8% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.82% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-122
On CISA KEVno
Public exploitnone known
Published2019-06-14
Last modified2026-06-17

Affected (26)

VendorProduct
canonicalubuntu linux
debiandebian linux
linuxlinux kernel
netappa700s
netappa700s firmware
netappactive iq unified manager
netappcn1610
netappcn1610 firmware
netapph610s
netapph610s firmware
netapphci management node
netappsolidfire
opensuseleap
redhatenterprise linux
redhatenterprise linux aus
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux for real time
redhatenterprise linux for real time for nfv
redhatenterprise linux for real time for nfv tus
redhatenterprise linux for real time tus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatvirtualization

References

→ the Explorer  ·  watch your stack  ·  NVD