kernel: memory leak in ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c
Published Nov 7, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.33%
Description
A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.
Affected products
No data.
Configuration 1
- ≤ 5.3.9
Configuration 2
- 30
- 31
Configuration 4
- 14.04
- 16.04
- 18.04
- 20.04
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.el7
Fixed · RHSA-2020:4060
Red Hat Enterprise Linux 7
kernel-alt-0:4.14.0-115.26.1.el7a
Fixed · RHSA-2020:2854
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.rt56.1131.el7
Fixed · RHSA-2020:4062
Red Hat Enterprise Linux 8
kernel-0:4.18.0-240.el8
Fixed · RHSA-2020:4431
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-240.rt7.54.el8
Fixed · RHSA-2020:4609
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise MRG 2
kernel
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.el7 | Fixed | RHSA-2020:4060 |
| Red Hat Enterprise Linux 7 | kernel-alt-0:4.14.0-115.26.1.el7a | Fixed | RHSA-2020:2854 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.rt56.1131.el7 | Fixed | RHSA-2020:4062 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-240.el8 | Fixed | RHSA-2020:4431 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-240.rt7.54.el8 | Fixed | RHSA-2020:4609 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is rated as having Moderate impact because it affects only specific hardware enabled systems.
Red Hat mitigation
In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module ccp. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/14/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-18808 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1777418 Issue Tracking
- https://github.com/torvalds/linux/commit/128c66429247add5128c03dc1e144ca56f05a4e2 x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYIFGYEDQXP5DVJQQUARQRK2PXKBKQGY/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YWWOOJKZ4NQYN4RMFIVJ3ZIXKJJI3MKP/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-18808
- https://security.netapp.com/advisory/ntap-20191205-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4525-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4526-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-18808
Change history (0)
No recorded changes yet.