VYPR
High severity7.8NVD Advisory· Published May 30, 2019· Updated Jun 17, 2026

CVE-2019-12454

CVE-2019-12454

Description

An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses kstrndup instead of kmemdup_nul, which allows attackers to have an unspecified impact via unknown vectors. NOTE: The vendor disputes this issues as not being a vulnerability because switching to kmemdup_nul() would only fix a security issue if the source string wasn't NUL-terminated, which is not the case

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Linux/Kernel2 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <=5.1.5
    • (no CPE)range: <=5.1.5
  • Linux/Linux kerneldescription

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.