Back

MEDIUM

kernel: memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c allows DoS

Published Nov 18, 2019

Description

A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a successful allocation has already occurred

Affected products

Remediation

Red Hat statement

This issue is rated as having Moderate impact because of the preconditions needed to trigger the resource cleanup code path.

Red Hat mitigation

In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module cfg80211. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 .

References (12)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Nov 18, 2019
Updated Aug 5, 2024
Reserved Nov 18, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 5, 2019
Bugzilla 1775074

ENISA EUVD

Assigner mitre
Published Nov 18, 2019
Updated Aug 5, 2024

GitHub

No data