CVE-2019-19072: Medium severity Canonical Ubuntu Linux vulnerability
A flaw was found in the way the predicateparse function in the tracing subsystem of the Linux kernel handled resource cleanup on error. This flaw allows an attacker with the ability to produce the error to crash the system.
Other sources
A memory leak in the predicateparse() function in kernel/trace/traceeventsfilter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
A memory leak in the predicateparse() function in kernel/trace/traceeventsfilter.c in the Linux kernel through 5.3.11 allows attackers to cause a DoS (memory consumption).
Upstream Reference:
https://github.com/torvalds/linux/commit/96c5c6e6a5b6db592acae039fed54b5c8844cd35
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.rt7.54.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-240.el8 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-19072?
CVE-2019-19072 is classified as a vulnerability that can lead to system crashes due to resource cleanup issues in the Linux kernel.
How do I fix CVE-2019-19072?
To fix CVE-2019-19072, you should update to the patched versions of the kernel provided by your Linux distribution.
What systems are affected by CVE-2019-19072?
CVE-2019-19072 affects various Linux distributions, including specific versions of Red Hat Enterprise Linux, Ubuntu, and Fedora.
Can CVE-2019-19072 be exploited remotely?
CVE-2019-19072 requires an attacker to have the ability to produce a specific error on the system, suggesting that it may not be directly exploitable remotely.
What is the impact of CVE-2019-19072?
The impact of CVE-2019-19072 is that it could lead to a denial-of-service condition by crashing affected systems.