CVE-2019-8980: High severity Linux Linux kernel vulnerability

Published Feb 18, 2019
·
Updated

A kernel memory leak was found in the kernelreadfile() function in the fs/exec.c file in the Linux kernel which allows attackers to cause a memory leak and thus a denial of service (DoS).

References:

https://lore.kernel.org/lkml/20190219021038.11340-1-yuehaibing@huawei.com/T/#u

https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1935698.html

An upstream patch:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f612acfae86af7ecad754ae6a46019be9da05b8e

Other sources

A kernel memory leak was found in the kernelreadfile() function in the fs/exec.c file in the Linux kernel. An attacker could use this flaw to cause a memory leak and thus a denial of service (DoS).

A memory leak in the kernelreadfile function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfsread failures.

Affected Software

15 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-193.rt13.51.el8
0:4.18.0-193.rt13.51.el8
redhat/kernel<0:4.18.0-193.el8
0:4.18.0-193.el8
Linux Linux kernel>=4.7<4.9.163
Linux Linux kernel>=4.14<4.14.106
Linux Linux kernel>=4.19<4.19.28
Linux Linux kernel>=4.20<4.20.15
Linux Linux kernel>=5.0<5.0.1
Linux Linux kernel=5.1-rc1
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
openSUSE Leap=15.0
Debian Debian Linux=8.0
debian/linux
6.1.176-16.1.180-16.12.94-16.12.107-17.1.12-17.1.13-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:4.18.0-193.rt13.51.el8
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:4.18.0-193.el8
  3. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1

Event History

Feb 18, 2019
CVE Published
12:00 AM
Feb 21, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Feb 22, 2019
Data Sourced
via Red Hat·11:49 AM
DescriptionSeverityAffected Software
Oct 16, 2025
Data Sourced
via Launchpad·04:31 AM
Description
Jul 4, 2026
Data Sourced
via Ubuntu·11:29 AM
RemedyDescriptionSeverityAffected Software
Sep 4, 2026
Data Sourced
via Debian·11:27 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2019-8980?

CVE-2019-8980 has a severity rating of medium due to its potential to cause a denial of service.

2

How do I fix CVE-2019-8980?

To fix CVE-2019-8980, update your kernel to versions 0:4.18.0-193.rt13.51.el8 or 0:4.18.0-193.el8 or later.

3

What systems are affected by CVE-2019-8980?

CVE-2019-8980 affects various Linux kernel versions between 4.7 and 5.1-rc1 and several Linux distributions like Red Hat, Ubuntu, and Debian.

4

Can CVE-2019-8980 be exploited remotely?

CVE-2019-8980 may allow local attackers to exploit the vulnerability to cause a memory leak.

5

What components are involved in CVE-2019-8980?

CVE-2019-8980 specifically involves the kernel_read_file() function within the fs/exec.c file of the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203