Severity
4.7MEDIUMNVD
EPSS
0.1%
top 77.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 24

Description

In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 4.19.28-1+3
debiandebian/linux< linux 4.19.28-1 (bookworm)
NVDopensuse/leap15.1

Also affects: Enterprise Linux 7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j78w-mvwv-rwcf: In the Linux kernel before 52022-05-24
OSV
CVE-2019-16994: In the Linux kernel before 52019-09-30

📋Vendor Advisories

2
Red Hat
kernel: Memory leak in sit_init_net() in net/ipv6/sit.c2019-09-30
Debian
CVE-2019-16994: linux - In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ip...2019

💬Community

2
Bugzilla
CVE-2019-16994 kernel: Memory leak in sit_init_net() in net/ipv6/sit.c [fedora-all]2019-10-08
Bugzilla
CVE-2019-16994 kernel: Memory leak in sit_init_net() in net/ipv6/sit.c2019-10-08