Home / Security / Advisories / NTAP-20190710-0002
NTAP-20190710-0002 — June 2019 Linux Kernel Vulnerabilities in NetApp Products
Published 2019-07-10 · Updated 2022-05-27 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product
Official advisory: NTAP-20190710-0002 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.
Product family: Baseboard management controllers · Active IQ Unified Manager · Other NetApp products · SolidFire / NetApp HCI | other NetApp product
CVEs in this advisory
- CVE-2019-12380 · site index
- CVE-2019-12379 · site index
- CVE-2019-12455 · site index
- CVE-2019-12614 · site index
- CVE-2019-12615 · site index
- CVE-2019-3846 · site index
- CVE-2019-12819 · site index
- CVE-2019-12818 · site index
- CVE-2019-10126 · site index
- CVE-2019-12881 · site index
- CVE-2019-3896 · site index
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Affected products
- AFF Baseboard Management Controller (BMC) - A700s
- Active IQ Unified Manager for VMware vSphere
- Cluster Network Switch (NetApp CN1610)
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire Baseboard Management Controller (BMC)
Official fixes
- NetApp HCI Baseboard Management Controller (BMC) - H610S — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H610S — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- AFF Baseboard Management Controller (BMC) - A700s — vendor fix ↗
- NetApp SolidFire & HCI Management Node — vendor fix ↗
- NetApp SolidFire & HCI Management Node — vendor fix ↗
References
- https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=4e78921ba4dd0aca1cc89168f4503 ↗
- https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty.git/commit/?h=tty-next&id=84ecc2f6eb1 ↗
- https://git.kernel.org/pub/scm/linux/kernel/git/sunxi/linux.git/commit/?h=sunxi/clk-for-5.3&id=f ↗
- https://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux.git/commit/?id=efa9ace68e487ddd29c2b4d ↗
- https://git.kernel.org/pub/scm/linux/kernel/git/davem/sparc.git/commit/?id=80caf43549e7e41a695c6d1e1 ↗
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6ff7b060535e87c2ae14dd854 ↗
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=58bdd544e2933a21a51eecf17 ↗
- https://gist.github.com/oxagast/472866fb2c3d439e10499d7141d0a520 ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2019