First published: Mon Nov 18 2019(Updated: )
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/linux | <5.3.0-26.28 | 5.3.0-26.28 |
ubuntu/linux | <5.4~ | 5.4~ |
ubuntu/linux-aws | <5.3.0-1009.10 | 5.3.0-1009.10 |
ubuntu/linux-aws | <5.4~ | 5.4~ |
ubuntu/linux-aws-5.0 | <5.4~ | 5.4~ |
ubuntu/linux-aws-hwe | <5.4~ | 5.4~ |
ubuntu/linux-azure | <5.3.0-1009.10 | 5.3.0-1009.10 |
ubuntu/linux-azure | <5.4~ | 5.4~ |
ubuntu/linux-azure-5.3 | <5.3.0-1009.10~18.04.1 | 5.3.0-1009.10~18.04.1 |
ubuntu/linux-azure-5.3 | <5.4~ | 5.4~ |
ubuntu/linux-azure-edge | <5.4~ | 5.4~ |
ubuntu/linux-gcp | <5.3.0-1011.12 | 5.3.0-1011.12 |
ubuntu/linux-gcp | <5.4~ | 5.4~ |
ubuntu/linux-gcp-5.3 | <5.3.0-1010.11~18.04.1 | 5.3.0-1010.11~18.04.1 |
ubuntu/linux-gcp-5.3 | <5.4~ | 5.4~ |
ubuntu/linux-gcp-edge | <5.4~ | 5.4~ |
ubuntu/linux-gke-4.15 | <5.4~ | 5.4~ |
ubuntu/linux-gke-5.0 | <5.4~ | 5.4~ |
ubuntu/linux-gke-5.3 | <5.4~ | 5.4~ |
ubuntu/linux-hwe | <5.4~ | 5.4~ |
ubuntu/linux-hwe-edge | <5.4~ | 5.4~ |
ubuntu/linux-kvm | <5.3.0-1009.10 | 5.3.0-1009.10 |
ubuntu/linux-kvm | <5.4~ | 5.4~ |
ubuntu/linux-lts-trusty | <5.4~ | 5.4~ |
ubuntu/linux-lts-xenial | <5.4~ | 5.4~ |
ubuntu/linux-oem | <5.4~ | 5.4~ |
ubuntu/linux-oem-5.4 | <5.4~ | 5.4~ |
ubuntu/linux-oem-osp1 | <5.4~ | 5.4~ |
ubuntu/linux-oracle | <5.3.0-1008.9 | 5.3.0-1008.9 |
ubuntu/linux-oracle | <5.4~ | 5.4~ |
ubuntu/linux-oracle-5.0 | <5.4~ | 5.4~ |
ubuntu/linux-raspi2 | <5.3.0-1015.17 | 5.3.0-1015.17 |
ubuntu/linux-raspi2 | <5.4~ | 5.4~ |
ubuntu/linux-raspi2-5.3 | <5.4~ | 5.4~ |
ubuntu/linux-snapdragon | <5.4~ | 5.4~ |
Linux Linux kernel | >=5.3<5.3.11 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Aff Baseboard Management Controller | ||
Netapp Cloud Backup | ||
Netapp Data Availability Services | ||
NetApp E-Series SANtricity OS Controller | =11.0 | |
NetApp E-Series SANtricity OS Controller | =11.0.0 | |
NetApp E-Series SANtricity OS Controller | =11.20 | |
NetApp E-Series SANtricity OS Controller | =11.25 | |
NetApp E-Series SANtricity OS Controller | =11.30 | |
NetApp E-Series SANtricity OS Controller | =11.30.5r3 | |
NetApp E-Series SANtricity OS Controller | =11.40 | |
NetApp E-Series SANtricity OS Controller | =11.40.3r2 | |
NetApp E-Series SANtricity OS Controller | =11.40.5 | |
NetApp E-Series SANtricity OS Controller | =11.50.1 | |
NetApp E-Series SANtricity OS Controller | =11.50.2 | |
NetApp E-Series SANtricity OS Controller | =11.50.2-p1 | |
NetApp E-Series SANtricity OS Controller | =11.60 | |
NetApp E-Series SANtricity OS Controller | =11.60.0 | |
NetApp E-Series SANtricity OS Controller | =11.60.1 | |
NetApp E-Series SANtricity OS Controller | =11.60.3 | |
NetApp E-Series SANtricity OS Controller | =11.70.1 | |
NetApp E-Series SANtricity OS Controller | =11.70.2 | |
Netapp Fas\/aff Baseboard Management Controller | ||
Netapp Hci Baseboard Management Controller | =h610s | |
Netapp Solidfire\, Enterprise Sds \& Hci Storage Node | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Steelstore Cloud Integrated Storage | ||
Broadcom Brocade Fabric Operating System Firmware | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
Netapp Solidfire Baseboard Management Controller Firmware | ||
Netapp Solidfire Baseboard Management Controller | ||
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
All of | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
All of | ||
Netapp Solidfire Baseboard Management Controller Firmware | ||
Netapp Solidfire Baseboard Management Controller | ||
debian/linux | 4.19.249-2 4.19.304-1 5.10.209-2 5.10.216-1 6.1.76-1 6.1.90-1 6.7.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-19044.
The title of the vulnerability is 'Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel.'
The severity of CVE-2019-19044 is not specified in the provided information.
An attacker can exploit CVE-2019-19044 by triggering kcalloc() or v3d_job_init() failures, causing a denial of service due to memory consumption.
To fix the CVE-2019-19044 vulnerability, update the Linux kernel to version 5.3.11 or later.