kernel: A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c allows for a DoS
Published Nov 18, 2019
7.5
HIGHCVSS 3.1
EPSS 3.61%
Description
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.
Affected products
No data.
Configuration 1
- ≥ 3.8 · < 4.4.262
- ≥ 4.5 · < 4.9.262
- ≥ 4.10 · < 4.14.226
- ≥ 4.15 · < 4.19.82
- ≥ 4.20 · < 5.3.9
Configuration 2
- n/a
- n/a
- n/a
- n/a
- 11.0
- 11.0.0
- 11.20
- 11.25
- 11.30
- 11.30.5r3
- 11.40
- 11.40.3r2
- 11.40.5
- 11.50.1
- 11.50.2
- 11.50.2
- 11.60
- 11.60.0
- 11.60.1
- 11.60.3
- 11.70.1
- 11.70.2
- n/a
- h610s
- n/a
- n/a
- n/a
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
Running on/with
- n/a
Configuration 5
- 14.04
- 16.04
- 18.04
- 19.04
- 19.10
- 15.1
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-19060 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1775035 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8699 Advisory
- https://github.com/torvalds/linux/commit/ab612b1daf415b62c58e130cb3d0f30b255a14d0 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19060
- https://security.netapp.com/advisory/ntap-20191205-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4208-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4210-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4226-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4364-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19060
Change history (0)
No recorded changes yet.