Use-after-free vulnerability in Linux kernel sound subsystem

Use-after-free vulnerability in Linux kernel sound subsystem

CVE-2019-15214 · MEDIUM Severity

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card disconnection causes certain data structures to be deleted too early. This is related to sound/core/init.c and sound/core/info.c.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.