PT-2019-4691 · Linux+4 · Linux Kernel+4

Mao Wenan

·

Published

2019-03-02

·

Updated

2021-07-21

·

CVE-2019-16994

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0
Description A memory leak exists in the sit init net() function in net/ipv6/sit.c when register netdev() fails to register sitn->fb tunnel dev. This issue may cause denial of service. The vulnerability is related to a resource not being released after its expiration, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.0, update to version 5.0 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Exploit

Fix

DoS

Missing Release of Resource after Effective Lifetime

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1506
ALT-PU-2019-1548
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2020-01063
CESA-2019_3309
CESA-2019_3517
CESA-2020_4060
CVE-2019-16994
OPENSUSE-SU-2020:0336-1
OPENSUSE-SU-2020_0336-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:4060
RHSA-2020:4062
RHSA-2020_4060
RHSA-2020_4062
SUSE-SU-2020:0511-1
SUSE-SU-2020:0558-1
SUSE-SU-2020:0559-1
SUSE-SU-2020:0560-1
SUSE-SU-2020:0580-1
SUSE-SU-2020:0584-1
SUSE-SU-2020:0599-1
SUSE-SU-2020:0605-1
SUSE-SU-2020:0613-1
SUSE-SU-2020:1663-1
SUSE-SU-2020_1663-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse