CVE-2019-10126: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.

A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Linux Linux Kernel: from 4.2, before 4.4.186 (fixed in 4.4.186); from 4.5, before 4.9.186 (fixed in 4.9.186); from 4.10, before 4.14.134 (fixed in 4.14.134); from 4.15, before 4.19.59 (fixed in 4.19.59); from 4.20, before 5.1.18 (fixed in 5.1.18)
  • Netapp a700s Firmware: affected versions not specified
  • Netapp Active Iq Unified Manager: from 9.5
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp h610s Firmware: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.7 only; version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For Real Time: version 7 only; version 8 only
  • Red Hat Enterprise Linux For Real Time For Nfv: version 7 only
  • Red Hat Enterprise Linux For Real Time For Nfv Tus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For Real Time Tus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.7 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Virtualization: version 4.0 only

Published 2019-06-14. Last modified 2026-06-17.