cbcvebase.
CVE-2019-19049
published 2019-11-18

CVE-2019-19049: A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service…

PriorityP433high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.55%
88.0th percentile
A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.3.15-1 (bookworm)linux 5.3.15-1 (bookworm)
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 3.17 < 4.4.2004.4.200
linuxlinux_kernel>= 4.10 < 4.14.1534.14.153
linuxlinux_kernel>= 4.15 < 4.19.834.19.83
linuxlinux_kernel>= 4.20 < 5.3.105.3.10
linuxlinux_kernel>= 4.5 < 4.9.2004.9.200
opensuseleap

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.