CVE-2019-19070 PUBLISHED

A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began

EPSS 0.68% · 71.4th percentile

Risk Scores

EPSS Score
0.68%
71.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-azure0, *, *
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-121.145~14.04.1, 0, 4.4.0-13.29~14.04.1
Ubuntu:18.04:LTSlinux-gcp-edge0, *, *
Ubuntu:18.04:LTSlinux-azure-edge4.18.0-1008.8~18.04.1, *, *
Ubuntu:Pro:14.04:LTSlinux3.13.0-54.91, 3.13.0-66.108, 3.13.0-65.105
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1002.2, 4.4.0-1118.124, 4.4.0-1059.63
Ubuntu:16.04:LTSlinux-hwe-edge0, 4.8.0-30.32~16.04.1, 4.8.0-34.36~16.04.1

Timeline

References

Open in Interactive Console →