Severity
7.5HIGHNVD
EPSS
2.0%
top 16.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 24

Description

In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel3.173.18.137+7
Debianlinux/linux_kernel< 4.19.37-1+3
debiandebian/linux< linux 4.19.37-1 (bookworm)
NVDopensuse/leap15.0, 15.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m4c2-gjmw-g8gc: In the Linux kernel before 52022-05-24
OSV
CVE-2019-16995: In the Linux kernel before 52019-09-30

📋Vendor Advisories

2
Red Hat
kernel: Memory leak in hsr_dev_finalize() in net/hsr/hsr_device.c2019-09-30
Debian
CVE-2019-16995: linux - In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in n...2019

💬Community

2
Bugzilla
CVE-2019-16995 kernel: Memory leak in hsr_dev_finalize() in net/hsr/hsr_device.c2019-10-08
Bugzilla
CVE-2019-16995 kernel: Memory leak in hsr_dev_finalize() in net/hsr/hsr_device.c [fedora-all]2019-10-08