CVE-2019-18813: High severity Linux Linux kernel vulnerability
A memory leak in the dwc3pciprobe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platformdeviceaddproperties() failures, aka CID-9bbfceea12a8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernel (drivers/usb/dwc3/dwc3-pci.c)to a version that resolves this vulnerability.Patch CID-9bbfceea12a8
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18813?
CVE-2019-18813 has been classified as a denial of service vulnerability due to a memory leak.
How do I fix CVE-2019-18813?
To fix CVE-2019-18813, upgrade to the patched versions such as 5.10.223-1, 5.10.226-1, or later.
Which Linux kernel versions are affected by CVE-2019-18813?
CVE-2019-18813 affects Linux kernel versions from 4.19 to 5.3.9.
Can CVE-2019-18813 be exploited remotely?
CVE-2019-18813 can potentially be exploited by attackers with local access to cause a denial of service.
What specific function is responsible for the vulnerability in CVE-2019-18813?
The vulnerability in CVE-2019-18813 originates from the dwc3_pci_probe() function in the Linux kernel.