CVE-2019-19082: Medium severity Linux Linux kernel vulnerability
Last updated 14 August 2026
Other sources
Memory leaks in createresourcepool() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption). This affects the dce120createresourcepool() function in drivers/gpu/drm/amd/display/dc/dce120/dce120resource.c, the dce110createresourcepool() function in drivers/gpu/drm/amd/display/dc/dce110/dce110resource.c, the dce100createresourcepool() function in drivers/gpu/drm/amd/display/dc/dce100/dce100resource.c, the dcn10createresourcepool() function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10resource.c, and the dce112createresourcepool() function in drivers/gpu/drm/amd/display/dc/dce112/dce112resource.c, aka CID-104c307147ad.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.8-1Fixed in 7.1.8-2
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19082?
CVE-2019-19082 has been classified as a high severity vulnerability due to its potential to cause denial of service through memory leaks.
How do I fix CVE-2019-19082?
To mitigate CVE-2019-19082, ensure your Linux kernel is updated to version 5.10.223-1 or later, 6.1.123-1 or later, or any of the fixed versions mentioned in the advisory.
Which versions of Linux are affected by CVE-2019-19082?
CVE-2019-19082 affects Linux kernels up to and including version 5.3.11.
What components are involved in CVE-2019-19082?
CVE-2019-19082 involves memory leaks in the create_resource_pool functions within the AMD display driver of the Linux kernel.
What impact does CVE-2019-19082 have on systems?
CVE-2019-19082 can lead to denial of service due to excessive memory consumption, potentially impacting system performance and availability.