First published: Mon Sep 30 2019(Updated: )
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=3.17<3.18.137 | |
Linux Linux kernel | >=4.4<4.4.177 | |
Linux Linux kernel | >=4.9<4.9.164 | |
Linux Linux kernel | >=4.14<4.14.107 | |
Linux Linux kernel | >=4.19<4.19.30 | |
Linux Linux kernel | >=4.20<4.20.17 | |
Linux Linux kernel | >=5.0<5.0.3 | |
Linux Linux kernel | =5.1-rc1 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Netapp Aff A700s Firmware | ||
NetApp AFF A700s | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H300e Firmware | ||
Netapp H300e | ||
Netapp H500e Firmware | ||
Netapp H500e | ||
Netapp H700e Firmware | ||
Netapp H700e | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
Netapp H610s Firmware | ||
Netapp H610s | ||
Netapp Data Availability Services | ||
Netapp Hci Management Node | ||
NetApp Service Processor | ||
Netapp Solidfire | ||
Netapp Steelstore Cloud Integrated Storage |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16995 is a vulnerability in the Linux kernel that allows a memory leak and may cause denial of service.
CVE-2019-16995 has a severity rating of 7.5 (High).
Versions before 5.0.3 of the Linux kernel are affected by CVE-2019-16995.
To fix CVE-2019-16995, update the Linux kernel to version 5.0.3 or higher.
More information about CVE-2019-16995 can be found at the following references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html), [Link 3](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.3).