CVE-2019-19046

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.31 % (70th)
0.31% Progress
Affected Products 3
Advisories 30
NVD Status Modified

A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control this failure at probe time

Weaknesses
CWE-401
Missing Release of Memory after Effective Lifetime
CVE Status
PUBLISHED
NVD Status
Modified
CNA
MITRE
Published Date
2019-11-18 06:15:11
(4 years ago)
Updated Date
2024-08-05 02:15:57
(6 weeks ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 5.3.11 and prior versions cpe:2.3:o:linux:linux_kernel <= 5.3.11

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 30 cpe:2.3:o:fedoraproject:fedora:30
  Fedoraproject Fedora 31 cpe:2.3:o:fedoraproject:fedora:31
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...