CVE-2019-19065 PUBLISHED

A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e. NOTE: This has been disputed as not a vulnerability because "rhashtable_init() can only fail if it is passed invalid values in the second parameter's struct, but when invoked from sdma_init() that is a pointer to a static const struct, so an attacker could only trigger failure if they could corrupt kernel memory (in which case a small memory leak is not a significant problem).

EPSS 0.05% · 14.8th percentile

Risk Scores

EPSS Score
0.05%
14.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-azure4.13.0-1011.14, 4.13.0-1007.9, 4.13.0-1006.8
Ubuntu:18.04:LTSlinux-gcp-5.30, 5.3.0-1008.9~18.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips4.15.0-1001.1, 0
Ubuntu:18.04:LTSlinux4.15.0-70.79, 4.15.0-69.78, 4.15.0-66.75
Ubuntu:22.04:LTSlinux-riscv5.15.0-1014.16, 5.15.0-1026.30, 5.15.0-1023.27
Ubuntu:18.04:LTSlinux-oracle0, 4.15.0-1007.9, 4.15.0-1008.10
Ubuntu:18.04:LTSlinux-kvm4.15.0-1050.50, 4.15.0-1047.47, 4.15.0-1046.46
Ubuntu:18.04:LTSlinux-raspi24.15.0-1044.47, 4.15.0-1045.49, 4.15.0-1047.51
Ubuntu:16.04:LTSlinux-gcp4.15.0-1029.31~16.04.1, 0, 4.10.0-1004.4
Ubuntu:18.04:LTSlinux-oem4.15.0-1012.15, 4.15.0-1013.16, 4.15.0-1033.38
Ubuntu:18.04:LTSlinux-gke-5.05.0.0-1025.26~18.04.1, 5.0.0-1026.27~18.04.2, 5.0.0-1022.22~18.04.3
Ubuntu:20.04:LTSlinux-riscv5.4.0-26.30, 5.4.0-37.42, 5.4.0-36.41
Ubuntu:16.04:LTSlinux-hwe-edge4.15.0-23.25~16.04.1, 4.13.0-25.29~16.04.2, 4.15.0-13.14~16.04.1
Ubuntu:18.04:LTSlinux-aws-5.00, 5.0.0-1021.24~18.04.1, 5.0.0-1022.25~18.04.1
Ubuntu:16.04:LTSlinux-oracle4.15.0-1021.23~16.04.1, 4.15.0-1029.32~16.04.1, 4.15.0-1027.30~16.04.1
Ubuntu:18.04:LTSlinux-azure5.0.0-1022.23~18.04.1, 5.0.0-1023.24~18.04.1, 5.0.0-1025.27~18.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1083.87+cvm1.1, 0, 5.4.0-1063.66+cvm2.2
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips4.15.0-2000.4, 0
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1035.37~16.04.1, 4.15.0-1054.56~16.04.1, 4.15.0-1052.54~16.04.1
Ubuntu:20.04:LTSlinux-gke5.4.0-1033.35, 5.4.0-1054.57, 5.4.0-1043.45

…and 20 more

Timeline

References

Open in Interactive Console →