First published: Mon Nov 18 2019(Updated: )
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=3.16<3.16.79 | |
Linux Kernel | >=3.17<4.4.201 | |
Linux Kernel | >=4.5<4.9.201 | |
Linux Kernel | >=4.10<4.14.154 | |
Linux Kernel | >=4.15<4.19.84 | |
Linux Kernel | >=4.20<5.3.11 | |
Oracle SD-WAN Edge | =8.2 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Ubuntu | =19.10 | |
Debian | =8.0 | |
SUSE Linux | =15.1 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp FAS/AFF Baseboard Management Controller | ||
NetApp Cloud Backup | ||
NetApp Data Availability Services | ||
NetApp E-Series SANtricity OS Controller | =11.0 | |
NetApp E-Series SANtricity OS Controller | =11.0.0 | |
NetApp E-Series SANtricity OS Controller | =11.20 | |
NetApp E-Series SANtricity OS Controller | =11.25 | |
NetApp E-Series SANtricity OS Controller | =11.30 | |
NetApp E-Series SANtricity OS Controller | =11.30.5r3 | |
NetApp E-Series SANtricity OS Controller | =11.40 | |
NetApp E-Series SANtricity OS Controller | =11.40.3r2 | |
NetApp E-Series SANtricity OS Controller | =11.40.5 | |
NetApp E-Series SANtricity OS Controller | =11.50.1 | |
NetApp E-Series SANtricity OS Controller | =11.50.2 | |
NetApp E-Series SANtricity OS Controller | =11.50.2-p1 | |
NetApp E-Series SANtricity OS Controller | =11.60 | |
NetApp E-Series SANtricity OS Controller | =11.60.0 | |
NetApp E-Series SANtricity OS Controller | =11.60.1 | |
NetApp E-Series SANtricity OS Controller | =11.60.3 | |
NetApp E-Series SANtricity OS Controller | =11.70.1 | |
NetApp E-Series SANtricity OS Controller | =11.70.2 | |
NetApp FAS/AFF Baseboard Management Controller | ||
NetApp HCI Baseboard Management Controller | =h610s | |
NetApp SolidFire Enterprise SDS | ||
NetApp SolidFire & HCI Management Node | ||
NetApp SteelStore Cloud Integrated Storage | ||
Broadcom Fabric Operating System | ||
NetApp HCI Compute Node Firmware | ||
NetApp HCI Compute Node | ||
NetApp SolidFire Baseboard Management Controller Firmware | ||
NetApp SolidFire | ||
All of | ||
NetApp HCI Compute Node Firmware | ||
NetApp HCI Compute Node | ||
All of | ||
NetApp SolidFire Baseboard Management Controller Firmware | ||
NetApp SolidFire | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19052 is classified as a denial of service vulnerability due to a memory leak that can lead to increased memory consumption.
To mitigate CVE-2019-19052, update to a kernel version that is 5.3.11 or later, or follow your distribution's security updates.
CVE-2019-19052 affects various Linux kernel versions prior to 5.3.11 across multiple distributions including Debian, Ubuntu, and others.
Attackers can exploit CVE-2019-19052 to cause a denial of service by triggering failures in usb_submit_urb(), leading to a memory leak.
CVE-2019-19052 was disclosed on November 29, 2024.