CVE-2019-19049: High severity linux kernel vulnerability
DISPUTED A memory leak in the unittestdataadd() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering offdtunflattentree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19049?
CVE-2019-19049 is considered to have a high severity due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2019-19049?
To fix CVE-2019-19049, users should upgrade their Linux kernel to version 5.3.10 or later.
What systems are affected by CVE-2019-19049?
CVE-2019-19049 affects various versions of the Linux kernel prior to 5.3.10, including versions ranging from 3.17 up to 5.3.
What exploits are associated with CVE-2019-19049?
CVE-2019-19049 allows attackers to trigger failures in the of_fdt_unflatten_tree() function, leading to memory leaks.
Is CVE-2019-19049 prevalent in openSUSE?
Yes, CVE-2019-19049 has been documented as affecting openSUSE Leap 15.1 and varies depending on the kernel version used.