kernel: memory leak in sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c
Published Nov 7, 2019
7.5
HIGHCVSS 3.1
EPSS 2.57%
Description
Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux kernel before 5.3.5 allow attackers to cause a denial of service (memory consumption) by triggering static_config_buf_prepare_for_upload() or sja1105_inhibit_tx() failures, aka CID-68501df92d11.
Affected products
No data.
- < 5.3.5
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2019-18807 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1777408 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.5 x_refsource_MISCMailing ListVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=68501df92d116b760777a2cfda314789f926476f x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-18807
- https://security.netapp.com/advisory/ntap-20191205-0001/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2019-18807
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-18807 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1777408 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.5 | x_refsource_MISCMailing ListVendor Advisory | |
| https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=68501df92d116b760777a2cfda314789f926476f | x_refsource_MISCMailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-18807 | ||
| https://security.netapp.com/advisory/ntap-20191205-0001/ | x_refsource_CONFIRM | |
| https://www.cve.org/CVERecord?id=CVE-2019-18807 |
Change history (0)
No recorded changes yet.