CVE-2019-19052: High severity Linux Linux kernel vulnerability
A memory leak in the gscanopen() function in drivers/net/can/usb/gsusb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usbsubmiturb() failures, aka CID-fb5be6a7b486.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernel (drivers/net/can/usb/gs_usb.c)to a version that resolves this vulnerability.Fixed in 5.3.11Patch CID-fb5be6a7b486
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19052?
CVE-2019-19052 is classified as a denial of service vulnerability due to a memory leak that can lead to increased memory consumption.
How do I fix CVE-2019-19052?
To mitigate CVE-2019-19052, update to a kernel version that is 5.3.11 or later, or follow your distribution's security updates.
What systems are affected by CVE-2019-19052?
CVE-2019-19052 affects various Linux kernel versions prior to 5.3.11 across multiple distributions including Debian, Ubuntu, and others.
What can attackers do with CVE-2019-19052?
Attackers can exploit CVE-2019-19052 to cause a denial of service by triggering failures in usb_submit_urb(), leading to a memory leak.
When was CVE-2019-19052 disclosed?
CVE-2019-19052 was disclosed on November 29, 2024.