VYPR
Unrated severityNVD Advisory· Published Dec 16, 2019· Updated Aug 5, 2024

CVE-2019-14604

CVE-2019-14604

Description

Null pointer dereference in Intel Quartus Prime Pro Edition FPGA kernel driver before 19.3 allows authenticated local users to cause denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Null pointer dereference in Intel Quartus Prime Pro Edition FPGA kernel driver before 19.3 allows authenticated local users to cause denial of service.

Vulnerability

A null pointer dereference vulnerability exists in the FPGA kernel driver component of Intel Quartus Prime Pro Edition software prior to version 19.3. The driver, used for FPGA programming and configuration, fails to properly validate a pointer before dereferencing it under specific conditions, leading to a crash. The issue is triggered by an authenticated user with local access [1].

Exploitation

An authenticated attacker with local access can exploit this vulnerability by performing operations that invoke the vulnerable code path in the FPGA kernel driver. The exact sequence is not publicly detailed, but it likely involves sending crafted IOCTL requests or other system calls that cause the driver to dereference a null pointer. No special privileges beyond standard user authentication are required [1].

Impact

Successful exploitation results in a denial of service (DoS) condition, causing the system or the driver to crash. The impact is limited to availability; no information disclosure, privilege escalation, or code execution is indicated [1].

Mitigation

Intel addressed this vulnerability in Quartus Prime Pro Edition version 19.3. Users should update to this version or later. No workarounds are provided in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the publication date [1].

References
  1. INTEL-SA-00311

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.