CVE-2019-19052: High severity Linux Linux kernel vulnerability
A memory leak in the gscanopen() function in drivers/net/can/usb/gsusb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usbsubmiturb() failures, aka CID-fb5be6a7b486.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.2.6-1Fixed in 7.2.7-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.3.11
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19052?
CVE-2019-19052 is classified as a denial of service vulnerability due to a memory leak that can lead to increased memory consumption.
How do I fix CVE-2019-19052?
To mitigate CVE-2019-19052, update to a kernel version that is 5.3.11 or later, or follow your distribution's security updates.
What systems are affected by CVE-2019-19052?
CVE-2019-19052 affects various Linux kernel versions prior to 5.3.11 across multiple distributions including Debian, Ubuntu, and others.
What can attackers do with CVE-2019-19052?
Attackers can exploit CVE-2019-19052 to cause a denial of service by triggering failures in usb_submit_urb(), leading to a memory leak.
When was CVE-2019-19052 disclosed?
CVE-2019-19052 was disclosed on November 29, 2024.