First published: Mon Nov 18 2019(Updated: )
A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-193.rt13.51.el8 | 0:4.18.0-193.rt13.51.el8 |
redhat/kernel | <0:4.18.0-193.el8 | 0:4.18.0-193.el8 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Linux kernel | <4.4.233 | |
Linux kernel | >=4.5<4.9.233 | |
Linux kernel | >=4.10<4.14.192 | |
Linux kernel | >=4.15<4.19.137 | |
Linux kernel | >=4.20<5.4 | |
Debian | =9.0 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Linux Kernel | <4.4.233 | |
Linux Kernel | >=4.5<4.9.233 | |
Linux Kernel | >=4.10<4.14.192 | |
Linux Kernel | >=4.15<4.19.137 | |
Linux Kernel | >=4.20<5.4 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19074 has a severity rating that indicates it can lead to a denial of service due to memory consumption.
To fix CVE-2019-19074, update your Linux kernel to version 5.10.223-1 or later, or apply the relevant updates from your Linux distribution.
CVE-2019-19074 affects various Linux kernels including versions through 5.3.11 and specific versions in Red Hat, Debian, and Ubuntu distributions.
CVE-2019-19074 enables attackers to exploit a memory leak, resulting in denial of service conditions.
There have been no confirmed reports of active exploitation for CVE-2019-19074, but mitigating the risk is recommended.