kernel: Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c allow for a DoS
Published Nov 18, 2019
4.4
MEDIUMCVSS 3.1
EPSS 0.47%
Description
Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading
Affected products
No data.
Configuration 1
- < 5.3.8
Configuration 2
- 18.04
- 19.04
- 19.10
- 15.1
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-193.el8
Fixed · RHSA-2020:1769
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-193.rt13.51.el8
Fixed · RHSA-2020:1567
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-193.el8 | Fixed | RHSA-2020:1769 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-193.rt13.51.el8 | Fixed | RHSA-2020:1567 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is rated as having Low impact because of the preconditions needed to trigger the error/resource cleanup code path.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-19067 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1774968 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1157180 x_refsource_MISCIssue TrackingThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.8 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8706 Advisory
- https://github.com/torvalds/linux/commit/57be09c6e8747bf48704136d9e3f92bfb93f5725 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19067
- https://usn.ubuntu.com/4208-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4226-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4526-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-19067
Change history (0)
No recorded changes yet.