kernel: memory allocation failure in the efi subsystem leads to denial of service
Published May 28, 2019
6.2
MEDIUMCVSS 3.0
EPSS 0.47%
Description
**DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prolog in arch/x86/platform/efi/efi_64.c mishandle memory allocation failures. NOTE: This id is disputed as not being an issue because “All the code touched by the referenced commit runs only at boot, before any user processes are started. Therefore, there is no possibility for an unprivileged user to control it.”.
Affected products
No data.
- ≤ 5.1.5
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Will not fix
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/108477 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-12380 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1715494 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4015 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=4e78921ba4dd0aca1cc89168f45039add4183f8e x_refsource_MISCMailing ListPatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-12380
- https://security.netapp.com/advisory/ntap-20190710-0002/ x_refsource_CONFIRM
- https://usn.ubuntu.com/4414-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4427-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4439-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-12380
Change history (0)
No recorded changes yet.