ISOMAN

CVE

CVE-2019-19067

Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading

Severity
MEDIUM
CVSS
4.4
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html
  2. https://bugzilla.suse.com/show_bug.cgi?id=1157180
  3. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.8
  4. https://github.com/torvalds/linux/commit/57be09c6e8747bf48704136d9e3f92bfb93f5725
  5. https://usn.ubuntu.com/4208-1/
  6. https://usn.ubuntu.com/4226-1/
  7. https://usn.ubuntu.com/4526-1/
  8. http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html
  9. https://bugzilla.suse.com/show_bug.cgi?id=1157180
  10. https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.8
  11. https://github.com/torvalds/linux/commit/57be09c6e8747bf48704136d9e3f92bfb93f5725
  12. https://usn.ubuntu.com/4208-1/
  13. https://usn.ubuntu.com/4226-1/
  14. https://usn.ubuntu.com/4526-1/