CVE-2019-19046: Medium severity Linux Linux kernel vulnerability
DISPUTED A memory leak in the ipmibmcregister() function in drivers/char/ipmi/ipmimsghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering idasimpleget() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control this failure at probe time.
Other sources
A memory leak problem was found in ipmibmcregister in drivers/char/ipmi/ipmimsghandler.c in Intelligent Platform Management Interface (IPMI) which is used for incoming and outgoing message routing purpose. This flaw may allow an attacker with minimal privilege to cause a denial of service by triggering idasimpleget() failure.
A memory leak problem was found in ipmibmcregister in drivers/char/ipmi/ipmimsghandler.c in Intelligent Platform Management Interface (IPMI) which is used for incoming and outgoing message routing. This flaw may allow an attacker with minimal privilege to cause a denial of service by triggering idasimpleget() failure.
Reference: https://bugzilla.suse.com/showbug.cgi?id=1157304 https://github.com/torvalds/linux/commit/4aa7afb0ee20a97fbf0c5bab3df028d5fb85fdab
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.rt56.1131.el7 - Upgrade
Upgrade
redhat/kernel-altto a version that resolves this vulnerability.Fixed in 0:4.14.0-115.29.1.el7a - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.65.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.40.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.rt7.54.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-19046?
CVE-2019-19046 has been classified as a denial of service vulnerability due to a memory leak.
How do I fix CVE-2019-19046?
To mitigate CVE-2019-19046, update your Linux kernel to versions 5.3.12 or later, or apply the respective patches from your distribution.
Which Linux distributions are affected by CVE-2019-19046?
CVE-2019-19046 affects multiple Linux distributions including certain versions of Red Hat, Debian, Fedora, and openSUSE.
What kind of attack can exploit CVE-2019-19046?
CVE-2019-19046 can be exploited by attackers to cause a denial of service by triggering memory consumption.
Is CVE-2019-19046 a low or high impact vulnerability?
CVE-2019-19046 is considered a high impact vulnerability as it can lead to service disruptions.