CVE-2019-19054: Medium severity Linux Linux kernel vulnerability
A memory leak in the cx23888irprobe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifoalloc() failures, aka CID-a7b2df76b42b.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernel (drivers/media/pci/cx23885/cx23888-ir.c, cx23888_ir_probe())to a version that resolves this vulnerability.Fixed in 5.3.11Patch CID-a7b2df76b42b
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19054?
CVE-2019-19054 has been classified as having a high severity due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2019-19054?
To fix CVE-2019-19054, upgrade to a patched version of the Linux kernel, specifically versions 5.10.223-1, 5.10.226-1, 6.1.119-1, or later.
What systems are affected by CVE-2019-19054?
CVE-2019-19054 affects the Linux kernel versions up to 5.3.11 and specific versions of Ubuntu and Fedora.
What symptoms indicate an exploitation of CVE-2019-19054?
Exploitation of CVE-2019-19054 may lead to system instability or crashes due to high memory consumption.
Is there a workaround for CVE-2019-19054 if I can't apply the update immediately?
A temporary workaround for CVE-2019-19054 could involve limiting the use of the related hardware or disabling the affected drivers.