CVE-2019-19055
|
** DISPUTED ** A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a successful allocation has already occurred.
Published:
November 18, 2019; 01:15:12 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19054
|
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19053
|
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy_from_iter_full() failures, aka CID-bbe692e349e2.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19052
|
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19051
|
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19050
|
A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19049
|
** DISPUTED ** A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19048
|
A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19047
|
A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, aka CID-c7ed6d0183d5.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19046
|
** DISPUTED ** A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control this failure at probe time.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19045
|
A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19044
|
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-19043
|
A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.
Published:
November 18, 2019; 01:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-18885
|
fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a crafted btrfs image because fs_devices->devices is mishandled within find_device, aka CID-09ba3bc9dd15.
Published:
November 14, 2019; 09:15:11 AM -05:00
|
V3.1: 5.5 MEDIUM
V2: 2.1 LOW
|
CVE-2010-2243
|
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results in an OOPS.
Published:
November 07, 2019; 12:15:12 PM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-18814
|
An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.
Published:
November 07, 2019; 11:15:11 AM -05:00
|
V3.1: 9.8 CRITICAL
V2: 7.5 HIGH
|
CVE-2019-18813
|
A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8.
Published:
November 07, 2019; 11:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-18812
|
A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-c0a333d842ef.
Published:
November 07, 2019; 11:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-18811
|
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
Published:
November 07, 2019; 11:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|
CVE-2019-18810
|
A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering drm_writeback_connector_init() failures, aka CID-a0ecd6fdbf5d.
Published:
November 07, 2019; 11:15:11 AM -05:00
|
V3.1: 7.5 HIGH
V2: 7.8 HIGH
|