CVE-2019-19060: High severity Linux Linux kernel vulnerability
A memory leak in the adisupdatescanmode() function in drivers/iio/imu/adisbuffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.3.9Patch CID-ab612b1daf41
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19060?
CVE-2019-19060 is considered to have a medium severity rating due to its potential to cause a denial of service through memory consumption.
How do I fix CVE-2019-19060?
To resolve CVE-2019-19060, upgrade the Linux kernel to version 5.3.9 or later.
What systems are affected by CVE-2019-19060?
CVE-2019-19060 affects various versions of the Linux kernel prior to 5.3.9, including certain versions of Ubuntu Linux and NetApp products.
Can CVE-2019-19060 lead to data loss?
While CVE-2019-19060 primarily results in a denial of service, it does not directly lead to data loss.
Is there a workaround for CVE-2019-19060?
There are no known workarounds for CVE-2019-19060; therefore, updating the kernel is the recommended course of action.