cbcvebase.
CVE-2019-19052
published 2019-11-18

CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.3.15-1 (bookworm)linux 5.3.15-1 (bookworm)
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 5.3.15-15.3.15-1
linuxlinux_kernel>= 0 < 4.4.0-171.2004.4.0-171.200
linuxlinux_kernel>= 0 < 4.15.0-74.844.15.0-74.84
linuxlinux_kernel>= 3.16 < 3.16.793.16.79
linuxlinux_kernel>= 3.17 < 4.4.2014.4.201
linuxlinux_kernel>= 4.10 < 4.14.1544.14.154
linuxlinux_kernel>= 4.15 < 4.19.844.19.84
linuxlinux_kernel>= 4.20 < 5.3.115.3.11
linuxlinux_kernel>= 4.5 < 4.9.2014.9.201
netappe-series_santricity_os_controller
netappe-series_santricity_os_controller
netappe-series_santricity_os_controller
netappe-series_santricity_os_controller
netappe-series_santricity_os_controller
netappe-series_santricity_os_controller

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL