An issue was discovered in drivers/scsi/qedi/qedidbg.c in the Linux kernel before 5.1.12. In the qedidbg_* family of functions, there is an out-of-bounds read.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-15090.json"
[
{
"digest": {
"line_hashes": [
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"190572305136452875365556151910641649701",
"311329909773667860857626175580047955574",
"41823827277319207355320522312106577195",
"78414947818405101309052789712444668746",
"259303026105170526568785410642782549723",
"133369692697983840023811668900579780217",
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"227468113711998787444200664527734392981",
"143180819864059056625959271329999797176",
"60235597624004886747289183449827868800",
"3342557565503029499558723826149351966",
"56854961860061151944181251748036909989",
"218714192544818179161149324446814248929",
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"101686758555460897870431823709301167803",
"33044576392790501127703270280449869541",
"205950217665327082790882488057729578351",
"97512708332154603763364719632823005836",
"71313297751547472751449597092290184437",
"120749044936794999607005507802021936484",
"59791303335340748802260267874988362511",
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"292169172730233198823622503139260501292",
"165750402524840729505014871233504443491",
"181465208924482347644814085414291482130",
"131921089717832730125860066917213484466",
"117107124533626934169297848716687178624",
"78967444849930269212197709482899932185"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c"
},
"signature_type": "Line",
"id": "CVE-2019-15090-21c1c673",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "340149024211297572115290190852844709635",
"length": 625.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_notice"
},
"signature_type": "Function",
"id": "CVE-2019-15090-56981aa9",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "54346876469815132600452960136396222918",
"length": 629.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_info"
},
"signature_type": "Function",
"id": "CVE-2019-15090-7f9e5499",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "336844299970299382926980631067620594802",
"length": 564.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_err"
},
"signature_type": "Function",
"id": "CVE-2019-15090-a6742438",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "60022705590296656539108715134174980201",
"length": 623.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_warn"
},
"signature_type": "Function",
"id": "CVE-2019-15090-aef913e9",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-15090.json"
[
{
"digest": {
"function_hash": "54346876469815132600452960136396222918",
"length": 629.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_info"
},
"signature_type": "Function",
"id": "CVE-2019-15090-3680c65d",
"source": "https://github.com/torvalds/linux/commit/c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "60022705590296656539108715134174980201",
"length": 623.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_warn"
},
"signature_type": "Function",
"id": "CVE-2019-15090-401fdfed",
"source": "https://github.com/torvalds/linux/commit/c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "340149024211297572115290190852844709635",
"length": 625.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_notice"
},
"signature_type": "Function",
"id": "CVE-2019-15090-60a1c35d",
"source": "https://github.com/torvalds/linux/commit/c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"function_hash": "336844299970299382926980631067620594802",
"length": 564.0
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c",
"function": "qedi_dbg_err"
},
"signature_type": "Function",
"id": "CVE-2019-15090-d181bb5e",
"source": "https://github.com/torvalds/linux/commit/c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"190572305136452875365556151910641649701",
"311329909773667860857626175580047955574",
"41823827277319207355320522312106577195",
"78414947818405101309052789712444668746",
"259303026105170526568785410642782549723",
"133369692697983840023811668900579780217",
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"227468113711998787444200664527734392981",
"143180819864059056625959271329999797176",
"60235597624004886747289183449827868800",
"3342557565503029499558723826149351966",
"56854961860061151944181251748036909989",
"218714192544818179161149324446814248929",
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"101686758555460897870431823709301167803",
"33044576392790501127703270280449869541",
"205950217665327082790882488057729578351",
"97512708332154603763364719632823005836",
"71313297751547472751449597092290184437",
"120749044936794999607005507802021936484",
"59791303335340748802260267874988362511",
"262277536629372291899844642030328227978",
"20492608553819819759896038265427460884",
"88112037859461101194697170772632081145",
"223992550940754385823967324371416230701",
"52276523208405866177328792461236509937",
"287308577094575590299996611885824461874",
"292169172730233198823622503139260501292",
"165750402524840729505014871233504443491",
"181465208924482347644814085414291482130",
"131921089717832730125860066917213484466",
"117107124533626934169297848716687178624",
"78967444849930269212197709482899932185"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/scsi/qedi/qedi_dbg.c"
},
"signature_type": "Line",
"id": "CVE-2019-15090-f0b254c5",
"source": "https://github.com/torvalds/linux/commit/c09581a52765a85f19fc35340127396d5e3379cc",
"deprecated": false
}
]