CVE-2019-15099: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.
drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only
- Linux Linux Kernel: from 4.14, before 4.14.157 (fixed in 4.14.157); from 4.15, before 4.19.87 (fixed in 4.19.87); from 4.20, before 5.3.14 (fixed in 5.3.14); from 5.4.0, before 5.4.1 (fixed in 5.4.1)
Published 2019-08-16. Last modified 2026-06-17.