kernel: dos in i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c
Published Nov 18, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.
Affected products
No data.
Configuration 1
- ≤ 5.3.11
Configuration 2
- 18.04
- 19.10
- 30
- 31
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is rated as having Moderate impact because of the preconditions needed to trigger the error code path.
Red Hat mitigation
In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module i40e. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 .
References (10)
- https://access.redhat.com/security/cve/CVE-2019-19043 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1774972 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8682 Advisory
- https://github.com/torvalds/linux/commit/27d461333459d282ffa4a2bdb6b215a59d493a8f x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3PSDE6PTOTVBK2YTKB2TFQP2SUBVSNF/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PY7LJMSPAGRIKABJPDKQDTXYW3L5RX2T/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-19043
- https://security.netapp.com/advisory/ntap-20191205-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4300-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19043
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-19043 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1774972 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8682 | Advisory | |
| https://github.com/torvalds/linux/commit/27d461333459d282ffa4a2bdb6b215a59d493a8f | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3PSDE6PTOTVBK2YTKB2TFQP2SUBVSNF/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PY7LJMSPAGRIKABJPDKQDTXYW3L5RX2T/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-19043 | ||
| https://security.netapp.com/advisory/ntap-20191205-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://usn.ubuntu.com/4300-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-19043 |
Change history (0)
No recorded changes yet.