imPC@ndo IT

Tracker / CVE-2019-19052

CVE-2019-19052

High 7.5

A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.

Affected products and versions

broadcom brocade_fabric_operating_system_firmware
canonical ubuntu_linux
debian debian_linux
linux linux_kernel · 3.16 → 3.16.79
linux linux_kernel · 3.17 → 4.4.201
linux linux_kernel · 4.10 → 4.14.154
linux linux_kernel · 4.15 → 4.19.84
linux linux_kernel · 4.20 → 5.3.11
linux linux_kernel · 4.5 → 4.9.201
netapp active_iq_unified_manager
netapp aff_baseboard_management_controller
netapp cloud_backup
netapp data_availability_services
netapp e-series_santricity_os_controller
netapp fas\/aff_baseboard_management_controller
netapp hci_baseboard_management_controller
netapp hci_compute_node_firmware
netapp solidfire\,_enterprise_sds_\&_hci_storage_node
netapp solidfire_\&_hci_management_node
netapp solidfire_baseboard_management_controller_firmware
netapp steelstore_cloud_integrated_storage
opensuse leap
oracle sd-wan_edge

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References