CVE-2019-19063: Medium severity Linux Linux kernel vulnerability
A flaw was found in the Linux kernel. The rtlusbprobe function mishandles resource cleanup on error. An attacker able to induce the error conditions could use this flaw to crash the system. The highest threat from this vulnerability is to system availability.
Other sources
Two memory leaks in the rtlusbprobe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.
Two memory leaks in the rtlusbprobe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption).
Upstream Issue:
https://github.com/torvalds/linux/commit/3f93616951138a598d930dcaec40f2bfd9ce43bb
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.rt56.1131.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.rt7.54.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Compensating control
Mitigate the Linux kernel flaw by preventing the affected Realtek module from loading: blacklist the kernel module rtl8192cu (per the referenced instructions for blacklisting kernel modules).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-19063?
The severity of CVE-2019-19063 is high as it affects system availability.
How do I fix CVE-2019-19063?
To fix CVE-2019-19063, update to the recommended kernel versions provided by the vendor.
What versions are affected by CVE-2019-19063?
CVE-2019-19063 affects multiple Linux kernel versions prior to 5.3.11 and specific vendor packages as identified.
Can CVE-2019-19063 be exploited remotely?
CVE-2019-19063 requires local access to the system for exploitation, as it manipulates kernel resources.
What systems are primarily impacted by CVE-2019-19063?
Systems running affected versions of the Linux kernel and related vendor packages, including Red Hat and Ubuntu, are primarily impacted.