CVE-2019-19067 PUBLISHED

Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading

EPSS 0.09% · 24.8th percentile

Risk Scores

EPSS Score
0.09%
24.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-gcp-5.35.3.0-1008.9~18.04.1, 0
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-fips4.15.0-1037.42, 4.15.0-1040.45, 0
Ubuntu:Pro:FIPS:18.04:LTSlinux-azure-fips4.15.0-1002.2, 0
Ubuntu:22.04:LTSlinux-riscv5.15.0-1015.17, 5.15.0-1014.16, 5.15.0-1012.13
Ubuntu:18.04:LTSlinux-gke-5.05.0.0-1020.20~18.04.1, 5.0.0-1022.22~18.04.3, 5.0.0-1023.23~18.04.2
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:16.04:LTSlinux-hwe4.15.0-43.46~16.04.1, 4.15.0-46.49~16.04.1, 4.15.0-47.50~16.04.1
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips0, 4.15.0-2000.4
Ubuntu:16.04:LTSlinux-oracle4.15.0-1046.50~16.04.1, 4.15.0-1050.54~16.04.1, 4.15.0-1007.9~16.04.1
Ubuntu:16.04:LTSlinux-gcp4.13.0-1019.23, 0, 4.10.0-1004.4
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1082.86~16.04.1, 0, 4.15.0-1030.31~16.04.1
Ubuntu:18.04:LTSlinux-kvm4.15.0-1025.25, 4.15.0-1023.23, 4.15.0-1021.21
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips0, 4.15.0-1001.1
Ubuntu:18.04:LTSlinux-oem-osp15.0.0-1028.32, 5.0.0-1030.34, 0
Ubuntu:16.04:LTSlinux-azure4.15.0-1061.66, 4.15.0-1063.68, 4.15.0-1064.69
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:18.04:LTSlinux-raspi24.15.0-1011.12, 4.15.0-1049.53, 4.15.0-1048.52
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1034.36, 4.15.0-1033.35, 4.15.0-1032.34
Ubuntu:18.04:LTSlinux-azure-5.35.3.0-1007.8~18.04.1, 0

…and 23 more

Timeline

References

Open in Interactive Console →