CVE-2019-19061: High severity Linux Linux kernel vulnerability
A memory leak in the adisupdatescanmodeburst() function in drivers/iio/imu/adisbuffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-9c0530e898f3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.3.9Patch CID-9c0530e898f3 - Compensating control
Mitigate denial of service by restricting untrusted access paths that could trigger the affected adis_update_scan_mode_burst() code path in drivers/iio/imu/adis_buffer.c until the kernel is upgraded to 5.3.9 (CID-9c0530e898f3).
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19061?
CVE-2019-19061 has a severity level that can lead to denial of service due to memory consumption.
How do I fix CVE-2019-19061?
To fix CVE-2019-19061, update to the Linux kernel version 5.3.9 or later.
Which Linux kernel versions are vulnerable to CVE-2019-19061?
CVE-2019-19061 affects Linux kernel versions prior to 5.3.9, including versions between 3.9 and 5.3.8.
What components are affected by CVE-2019-19061?
CVE-2019-19061 specifically affects the adis_update_scan_mode_burst() function in the IIO IMU drivers of the Linux kernel.
Can CVE-2019-19061 lead to data breaches?
CVE-2019-19061 does not directly facilitate data breaches, but it can result in a denial of service, affecting system availability.