Bug 1157039 - (CVE-2019-19079) VUL-0: CVE-2019-19079: kernel-source: A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c
(CVE-2019-19079)
VUL-0: CVE-2019-19079: kernel-source: A memory leak in the qrtr_tun_write_ite...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Major
: ---
Assigned To: E-mail List
Security Team bot
https://smash.suse.de/issue/247517/
CVSSv3:SUSE:CVE-2019-19079:7.5:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-11-18 14:30 UTC by Robert Frohl
Modified: 2019-12-05 12:53 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2019-11-18 14:30:08 UTC
CVE-2019-19079

A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c in the
Linux kernel before 5.3 allows attackers to cause a denial of service (memory
consumption), aka CID-a21b7f0cff19.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-19079
https://github.com/torvalds/linux/commit/a21b7f0cff1906a93a0130b74713b15a0b36481d
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19079
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3
Comment 1 Robert Frohl 2019-11-18 14:31:00 UTC
I believe this does not affect us, code introduced with 4.18. Couldn't find a backport.