CVE-2019-19050

Description

A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.089

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-gcp_5.0.0.1029.33_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-gke-5.0_5.0.0.1029.17_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-aws-edge_5.0.0.1024.38_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-oracle-edge_5.0.0.1010.9_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-5.0.0-1024-aws_5.0.0-1024.27~18.04.1_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-5.0.0-1029-gcp_5.0.0-1029.30~18.04.1_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-5.0.0-1029-gke_5.0.0-1029.30~18.04.1_amd64.debLinux
Linux kernel for Amazon Web Services (AWS) systems (USN-4258-1) linux-image-5.0.0-1010-oracle_5.0.0-1010.15~18.04.1_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-aws_5.3.0.1011.13_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-gcp_5.3.0.1012.13_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-gke_5.3.0.1012.13_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-kvm_5.3.0.1010.12_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-oracle_5.3.0.1009.10_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-generic_5.3.0.40.34_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-virtual_5.3.0.40.34_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-gcp-edge_5.3.0.1012.11_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-azure-edge_5.3.0.1013.13_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-lowlatency_5.3.0.40.34_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-1010-kvm_5.3.0-1010.11_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-1011-aws_5.3.0-1011.12_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-1012-gcp_5.3.0-1012.13_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-1012-gcp_5.3.0-1012.13~18.04.1_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-1013-azure_5.3.0-1013.14~18.04.1_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-40-generic_5.3.0-40.32_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-40-generic_5.3.0-40.32~18.04.1_i386.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-40-generic_5.3.0-40.32~18.04.1_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-1009-oracle_5.3.0-1009.10_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-generic-hwe-18.04_5.3.0.40.97_i386.debLinux
Linux kernel (USN-4284-1) linux-image-generic-hwe-18.04_5.3.0.40.97_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-virtual-hwe-18.04_5.3.0.40.97_i386.debLinux
Linux kernel (USN-4284-1) linux-image-virtual-hwe-18.04_5.3.0.40.97_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-40-lowlatency_5.3.0-40.32_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-40-lowlatency_5.3.0-40.32~18.04.1_i386.debLinux
Linux kernel (USN-4284-1) linux-image-5.3.0-40-lowlatency_5.3.0-40.32~18.04.1_amd64.debLinux
Linux kernel (USN-4284-1) linux-image-lowlatency-hwe-18.04_5.3.0.40.97_i386.debLinux
Linux kernel (USN-4284-1) linux-image-lowlatency-hwe-18.04_5.3.0.40.97_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234