CVE-2019-19049Missing Release of Memory after Effective Lifetime in Kernel

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 24

Description

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel3.174.4.200+4
Debianlinux/linux_kernel< 5.3.15-1+3
debiandebian/linux< linux 5.3.15-1 (bookworm)
NVDopensuse/leap15.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-37hw-m3rc-6ww4: A memory leak in the unittest_data_add() function in drivers/of/unittest2022-05-24
OSV
CVE-2019-19049: A memory leak in the unittest_data_add() function in drivers/of/unittest2019-11-18

📋Vendor Advisories

2
Red Hat
kernel: dos in unittest_data_add() function in drivers/of/unittest.c2019-11-18
Debian
CVE-2019-19049: linux - A memory leak in the unittest_data_add() function in drivers/of/unittest.c in th...2019

💬Community

2
Bugzilla
CVE-2019-19049 kernel: dos in unittest_data_add() function in drivers/of/unittest.c [fedora-all]2019-11-21
Bugzilla
CVE-2019-19049 kernel: dos in unittest_data_add() function in drivers/of/unittest.c2019-11-21