ISOMAN

CVE

CVE-2019-19047

A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, aka CID-c7ed6d0183d5.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.11
  2. https://github.com/torvalds/linux/commit/c7ed6d0183d5ea9bc31bcaeeba4070bd62546471
  3. https://security.netapp.com/advisory/ntap-20191205-0001/
  4. https://usn.ubuntu.com/4225-1/
  5. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.11
  6. https://github.com/torvalds/linux/commit/c7ed6d0183d5ea9bc31bcaeeba4070bd62546471
  7. https://security.netapp.com/advisory/ntap-20191205-0001/
  8. https://usn.ubuntu.com/4225-1/