CVE-2019-18809

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.

References

http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html

https://github.com/torvalds/linux/commit/2289adbfa559050d2a38bcd9caac1c18b800e928

https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/LYIFGYEDQXP5DVJQQUARQRK2PXKBKQGY/

https://lists.fedoraproject.org/archives/list/[email protected]/message/YWWOOJKZ4NQYN4RMFIVJ3ZIXKJJI3MKP/

https://security.netapp.com/advisory/ntap-20191205-0001/

https://usn.ubuntu.com/4285-1/

https://usn.ubuntu.com/4287-1/

https://usn.ubuntu.com/4287-2/

https://usn.ubuntu.com/4300-1/

Details

Source: MITRE

Published: 2019-11-07

Updated: 2020-08-24

Type: CWE-401

Risk Information

CVSS v2

Base Score: 4.9

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 4.6

Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 0.9

Severity: MEDIUM

Tenable Plugins

View all (21 total)

IDNameProductFamilySeverity
145806CentOS 8 : kernel (CESA-2020:4431)NessusCentOS Local Security Checks
medium
142430RHEL 8 : kernel (RHSA-2020:4431)NessusRed Hat Local Security Checks
medium
142382RHEL 8 : kernel-rt (RHSA-2020:4609)NessusRed Hat Local Security Checks
medium
135574Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5649)NessusOracle Linux Local Security Checks
medium
134658Ubuntu 18.04 LTS / 19.10 : Linux kernel vulnerabilities (USN-4300-1)NessusUbuntu Local Security Checks
medium
134486EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1197)NessusHuawei Local Security Checks
critical
134363SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:0613-1)NessusSuSE Local Security Checks
critical
134240Debian DLA-2114-1 : linux-4.9 security updateNessusDebian Local Security Checks
critical
133800Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4287-1)NessusUbuntu Local Security Checks
high
133798Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-4285-1)NessusUbuntu Local Security Checks
high
132925SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0093-1)NessusSuSE Local Security Checks
critical
132796EulerOS Virtualization for ARM 64 3.0.5.0 : kernel (EulerOS-SA-2020-1042)NessusHuawei Local Security Checks
critical
132394SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:3381-1)NessusSuSE Local Security Checks
critical
132389SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2019:3371-1)NessusSuSE Local Security Checks
critical
132237SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:3317-1)NessusSuSE Local Security Checks
critical
132236SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3316-1)NessusSuSE Local Security Checks
critical
132032openSUSE Security Update : the Linux Kernel (openSUSE-2019-2675)NessusSuSE Local Security Checks
critical
131833SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3200-1)NessusSuSE Local Security Checks
high
131787Fedora 30 : kernel (2019-124a241044)NessusFedora Local Security Checks
medium
131742Fedora 31 : kernel (2019-b86a7bdba0)NessusFedora Local Security Checks
medium
131349EulerOS 2.0 SP8 : kernel (EulerOS-SA-2019-2283)NessusHuawei Local Security Checks
high