PT-2019-3978 · Linux+5 · Linux Kernel+5

Published

2019-10-28

·

Updated

2021-05-28

·

CVE-2019-18811

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.3.9
Description The issue is related to a memory leak in the sof set get large ctrl data() function, located in sound/soc/sof/ipc.c. This memory leak can be triggered by causing sof get ctrl copy params() failures, leading to a denial of service due to memory consumption. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Linux kernel versions through 5.3.9, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Leak

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1578
ALT-PU-2019-3113
ALT-PU-2019-3136
ALT-PU-2019-3184
ALT-PU-2020-1198
ALT-PU-2020-1421
ALT-PU-2020-1450
ALT-PU-2020-1501
ALT-PU-2020-1714
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-04509
CESA-2021_1578
CVE-2019-18811
RHSA-2021:1578
RHSA-2021_1578
USN-4284-1

Affected Products

Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Ubuntu