CVE-2019-19050

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 7.8 (High)
78% Progress
EPSS 1.49 % (87th)
1.49% Progress
Affected Products 22
Advisories 17

A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.

Weaknesses
CWE-401
Missing Release of Memory after Effective Lifetime
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-11-18 06:15:11
(4 years ago)
Updated Date
2023-11-07 03:07:24
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 4.20 version and prior 5.3.16 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.3.16
  Linux Kernel from 5.4 version and prior 5.4.3 version cpe:2.3:o:linux:linux_kernel >= 5.4 < 5.4.3
  Linux Kernel 5.5 Rc1 cpe:2.3:o:linux:linux_kernel:5.5:rc1

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 30 cpe:2.3:o:fedoraproject:fedora:30
  Fedoraproject Fedora 31 cpe:2.3:o:fedoraproject:fedora:31

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts
  Canonical Ubuntu Linux 19.10 cpe:2.3:o:canonical:ubuntu_linux:19.10

Configuration #4

    CPE23 From Up To
  Netapp Active Iq Unified Manager for Vmware Vsphere cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere
  Netapp Data Availability Services cpe:2.3:a:netapp:data_availability_services:-
  Netapp E-series Santricity Os Controller from 11.0.0 version and 11.60.3 and prior versions cpe:2.3:a:netapp:e-series_santricity_os_controller >= 11.0.0 <= 11.60.3
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-
  Netapp Steelstore Cloud Integrated Storage cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-
  Netapp Hci Compute Node cpe:2.3:h:netapp:hci_compute_node:-
  Netapp Hci Storage Node cpe:2.3:h:netapp:hci_storage_node:-
  Broadcom Fabric Operating System cpe:2.3:o:broadcom:fabric_operating_system:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp Aff A700s Firmware cpe:2.3:o:netapp:aff_a700s_firmware:-
OR  
  Running on/with
  Netapp Aff A700s cpe:2.3:h:netapp:aff_a700s:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp Fas8300 Firmware cpe:2.3:o:netapp:fas8300_firmware:-
OR  
  Running on/with
  Netapp Fas8300 cpe:2.3:h:netapp:fas8300:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp Fas8700 Firmware cpe:2.3:o:netapp:fas8700_firmware:-
OR  
  Running on/with
  Netapp Fas8700 cpe:2.3:h:netapp:fas8700:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp Aff A400 Firmware cpe:2.3:o:netapp:aff_a400_firmware:-
OR  
  Running on/with
  Netapp Aff A400 cpe:2.3:h:netapp:aff_a400:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H610s Firmware cpe:2.3:o:netapp:h610s_firmware:-
OR  
  Running on/with
  Netapp H610s cpe:2.3:h:netapp:h610s:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...