CVE-2019-19073Missing Release of Memory after Effective Lifetime in Linux

Severity
4.0MEDIUMNVD
OSV5.5OSV4.7
EPSS
0.1%
top 75.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateDec 30

Description

Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, and the htc_connect_service() function, aka CID-853acf7caf10.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.5 | Impact: 1.4

Affected Packages5 packages

Debianlinux/linux_kernel< 5.4.6-1+3
Ubuntulinux/linux_kernel< 4.4.0-190.220+1
NVDlinux/linux_kernel5.3.11
debiandebian/linux< linux 5.4.6-1 (bookworm)
NVDopensuse/leap15.1

Also affects: Fedora 30, 31

Patches

🔴Vulnerability Details

4
GHSA
GHSA-rg5g-mjfh-w75q: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst2022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities2020-09-24
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2020-09-23
OSV
CVE-2019-19073: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst2019-11-18

📋Vendor Advisories

4
Ubuntu
Linux kernel vulnerabilities2020-09-24
Ubuntu
Linux kernel vulnerabilities2020-09-23
Red Hat
kernel: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel (DOS)2019-11-21
Debian
CVE-2019-19073: linux - Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel thr...2019

📄Research Papers

1
arXiv
Similar but Patched Code Considered Harmful -- The Impact of Similar but Patched Code on Recurring Vulnerability Detection and How to Remove Them2024-12-30

💬Community

2
Bugzilla
CVE-2019-19073 kernel: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel (DOS)2019-11-21
Bugzilla
CVE-2019-19073 kernel: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a DoS [fedora-all]2019-11-21