CVE-2019-15917: Debian Linux

High severity, CVSS 7.0. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: from 3.12.61, before 3.13 (fixed in 3.13); from 4.7, before 4.9.202 (fixed in 4.9.202); from 4.10, before 4.14.109 (fixed in 4.14.109); from 4.15, before 4.19.32 (fixed in 4.19.32); from 4.20, before 5.0.5 (fixed in 5.0.5)
  • Opensuse Leap: version 15.0 only; version 15.1 only

Published 2019-09-04. Last modified 2026-06-17.