kernel: memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c leads to DoS
Published Nov 18, 2019
7.5
HIGHCVSS 3.1
EPSS 3.30%
Description
A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c in the Linux kernel before 5.3 allows attackers to cause a denial of service (memory consumption), aka CID-a21b7f0cff19.
Affected products
No data.
Configuration 1
- ≥ 4.18 · < 4.19.89
- ≥ 4.20 · < 5.3
Configuration 2
- 18.04
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
There was no shipped kernel version were seen affected with this problem. These files are not built in our source code.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-19079 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1776367 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8718 Advisory
- https://github.com/torvalds/linux/commit/a21b7f0cff1906a93a0130b74713b15a0b36481d x_refsource_MISCPatchTool Signature
- https://nvd.nist.gov/vuln/detail/CVE-2019-19079
- https://security.netapp.com/advisory/ntap-20191205-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4258-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19079
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-19079 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1776367 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8718 | Advisory | |
| https://github.com/torvalds/linux/commit/a21b7f0cff1906a93a0130b74713b15a0b36481d | x_refsource_MISCPatchTool Signature | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-19079 | ||
| https://security.netapp.com/advisory/ntap-20191205-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://usn.ubuntu.com/4258-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-19079 |
Change history (0)
No recorded changes yet.