CVE-2019-15291: Linux Kernel

Medium severity, CVSS 4.6. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver.

Affected products

  • Linux Linux Kernel: up to and including 5.2.9

Published 2019-08-20. Last modified 2026-06-17.