CVE-2019-19050: High severity linux kernel vulnerability
A memory leak in the cryptoreportstat() function in crypto/cryptouserstat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering cryptoreportstatalg() failures, aka CID-c03b04dcdba1.
Other sources
A vulnerability was found in Linux Kernel where, a memory leak in the cryptoreportstat() function in crypto/cryptouserstat.c allows attackers to cause a denial of service (memory consumption) by triggering cryptoreportstatalg() failures.
Reference: https://github.com/torvalds/linux/commit/c03b04dcdba1da39903e23cc4d072abf8f68f2dd
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19050?
CVE-2019-19050 is classified as a high severity vulnerability due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2019-19050?
To mitigate CVE-2019-19050, upgrade your Linux kernel to version 5.4.4 or later, or apply appropriate patches provided by your distribution.
What systems are affected by CVE-2019-19050?
CVE-2019-19050 affects various versions of the Linux Kernel up to 5.3.11 and certain Fedora and Ubuntu releases.
Can CVE-2019-19050 be exploited remotely?
Yes, CVE-2019-19050 can potentially be exploited remotely if an attacker can trigger the crypto_reportstat_alg() function failures.
What type of vulnerability is CVE-2019-19050?
CVE-2019-19050 is a memory leak vulnerability that can lead to denial of service scenarios.