CVE-2019-14604
Description
Null pointer dereference in Intel Quartus Prime Pro Edition FPGA kernel driver before 19.3 allows authenticated local users to cause denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Null pointer dereference in Intel Quartus Prime Pro Edition FPGA kernel driver before 19.3 allows authenticated local users to cause denial of service.
Vulnerability
A null pointer dereference vulnerability exists in the FPGA kernel driver component of Intel Quartus Prime Pro Edition software prior to version 19.3. The driver, used for FPGA programming and configuration, fails to properly validate a pointer before dereferencing it under specific conditions, leading to a crash. The issue is triggered by an authenticated user with local access [1].
Exploitation
An authenticated attacker with local access can exploit this vulnerability by performing operations that invoke the vulnerable code path in the FPGA kernel driver. The exact sequence is not publicly detailed, but it likely involves sending crafted IOCTL requests or other system calls that cause the driver to dereference a null pointer. No special privileges beyond standard user authentication are required [1].
Impact
Successful exploitation results in a denial of service (DoS) condition, causing the system or the driver to crash. The impact is limited to availability; no information disclosure, privilege escalation, or code execution is indicated [1].
Mitigation
Intel addressed this vulnerability in Quartus Prime Pro Edition version 19.3. Users should update to this version or later. No workarounds are provided in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Intel/FPGA kernel driver for Quartus Prime Pro Editiondescription
- Range: <19.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00311.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.