cbcvebase.
CVE-2019-17075
published 2019-10-01

CVE-2019-17075: An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.24%
92.8th percentile
An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single (a DMA function) from a stack variable. This could allow an attacker to trigger a Denial of Service, exploitable if this driver is used on an architecture for which this stack/DMA interaction has security relevance.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.3.7-1 (bookworm)linux 5.3.7-1 (bookworm)
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 5.3.7-15.3.7-1
linuxlinux_kernel>= 0 < 4.4.0-170.1994.4.0-170.199
linuxlinux_kernel>= 0 < 4.15.0-72.814.15.0-72.81
linuxlinux_kernel>= 2.6.35 < 4.4.1984.4.198
linuxlinux_kernel>= 4.10 < 4.14.1514.14.151
linuxlinux_kernel>= 4.15 < 4.19.814.19.81
linuxlinux_kernel>= 4.20 < 5.3.85.3.8
linuxlinux_kernel>= 4.5.0 < 4.9.1984.9.198

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.