CVE-2019-19049

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 7.8 (High)
78% Progress
EPSS 0.25 % (65th)
0.25% Progress
Affected Products 2
Advisories 13
NVD Status Analyzed

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot

Weaknesses
CWE-401
Missing Release of Memory after Effective Lifetime
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
MITRE
Published Date
2019-11-18 06:15:11
(4 years ago)
Updated Date
2024-08-27 18:44:14
(2 weeks ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 3.17 version and prior 4.4.200 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 4.4.200
  Linux Kernel from 4.5 version and prior 4.9.200 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.200
  Linux Kernel from 4.10 version and prior 4.14.153 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.153
  Linux Kernel from 4.15 version and prior 4.19.83 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.83
  Linux Kernel from 4.20 version and prior 5.3.10 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.3.10

Configuration #2

    CPE23 From Up To
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...