CVE-2019-19066 PUBLISHED

A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.

EPSS 0.08% · 24.3th percentile

Risk Scores

EPSS Score
0.08%
24.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-oracle4.15.0-1008.10, 4.15.0-1007.9, 0
Ubuntu:18.04:LTSlinux-kvm4.15.0-1011.11, 4.15.0-1012.12, 4.15.0-1016.16
Ubuntu:16.04:LTSlinux-azure4.11.0-1011.11, 4.15.0-1071.76, 4.15.0-1069.74
Ubuntu:18.04:LTSlinux-oem4.15.0-1028.33, 4.15.0-1030.35, 4.15.0-1033.38
Ubuntu:18.04:LTSlinux-raspi24.15.0-1013.14, 4.15.0-1012.13, 4.15.0-1011.12
Ubuntu:16.04:LTSlinux-raspi24.4.0-1057.64, 4.4.0-1128.137, 4.4.0-1127.136
Ubuntu:16.04:LTSlinux-hwe-edge4.15.0-23.25~16.04.1, 4.15.0-22.24~16.04.1, 4.15.0-20.21~16.04.1
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-17.18~18.04.1, 5.0.0-19.20~18.04.1, 5.0.0-20.21~18.04.1
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1067.72~14.04.1, 4.15.0-1059.64~14.04.1, 4.15.0-1057.62~14.04.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1042.44, 4.15.0-1044.46, 4.15.0-1045.48
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1055.59, 0, 4.4.0-1012.12
Ubuntu:18.04:LTSlinux-raspi2-5.35.3.0-1017.19~18.04.1, 0, 5.3.0-1018.20~18.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-34.53~14.04.1, 4.4.0-36.55~14.04.1, 4.4.0-38.57~14.04.1
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1007.8, 5.3.0-1014.16
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1017.17, 4.4.0-1012.12, 4.4.0-1014.14
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:18.04:LTSlinux-aws4.15.0-1001.1, 4.15.0-1003.3, 4.15.0-1005.5
Ubuntu:18.04:LTSlinux-azure-edge4.18.0-1007.7~18.04.1, 4.18.0-1008.8~18.04.1, 4.18.0-1006.6~18.04.1
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1025.30, 0, 4.4.0-1003.3

…and 31 more

Timeline

References

Open in Interactive Console →