CVE-2019-19076 PUBLISHED

A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted

EPSS 2.33% · 84.7th percentile

Risk Scores

EPSS Score
2.33%
84.7th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-riscv5.15.0-1023.27, 5.15.0-1026.30, 5.15.0-1027.31
Ubuntu:20.04:LTSlinux-raspi25.3.0-1015.17, 5.3.0-1017.19, 5.4.0-1004.4
Ubuntu:18.04:LTSlinux-aws-5.00, 5.0.0-1021.24~18.04.1
Ubuntu:20.04:LTSlinux-riscv0, 5.4.0-40.45, 5.4.0-39.44
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1013.14~18.04.1, 0, 4.18.0-1004.5~18.04.1
Ubuntu:18.04:LTSlinux-oracle-5.00, 5.0.0-1007.12~18.04.1
Ubuntu:18.04:LTSlinux-azure-edge4.18.0-1006.6~18.04.1, 5.0.0-1012.12~18.04.2, 4.18.0-1008.8~18.04.1
Ubuntu:18.04:LTSlinux-hwe4.18.0-16.17~18.04.1, 4.18.0-17.18~18.04.1, 4.18.0-18.19~18.04.1
Ubuntu:16.04:LTSlinux-hwe-edge0, 4.8.0-28.30~16.04.1, 4.8.0-30.32~16.04.1
Ubuntu:18.04:LTSlinux-hwe-edge5.0.0-17.18~18.04.1, 5.3.0-24.26~18.04.2, 5.3.0-23.25~18.04.2
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:18.04:LTSlinux-azure4.18.0-1014.14~18.04.1, 4.18.0-1013.13~18.04.1, 4.18.0-1011.11~18.04.1
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1094.98, 0, 5.4.0-1008.9
Ubuntu:20.04:LTSlinux-gke5.4.0-1090.97, 5.4.0-1053.56, 5.4.0-1052.55
Ubuntu:18.04:LTSlinux-oem-osp15.0.0-1028.32, 5.0.0-1027.31, 0
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:18.04:LTSlinux-gcp4.15.0-1026.27, 4.15.0-1037.39, 4.15.0-1036.38
Ubuntu:20.04:LTSlinux-gkeop-5.155.15.0-1019.24~20.04.1, 5.15.0-1020.25~20.04.1, 5.15.0-1021.26~20.04.1
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:20.04:LTSlinux-azure-fde0, 5.4.0-1063.66+cvm2.2, 5.4.0-1063.66+cvm3.2

…and 1 more

Timeline

References

Open in Interactive Console →