Vulnerability Name:

CVE-2019-19072 (CCN-171801)

Assigned:2019-09-20
Published:2019-09-20
Updated:2020-08-24
Summary:A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
CVSS v3 Severity:4.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
3.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.4 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
3.9 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-401
CWE-400
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-19072

Source: XF
Type: UNKNOWN
linux-kernel-cve201919072-dos(171801)

Source: CCN
Type: Linux Kernel GIT Repository
tracing: Have error path in predicate_parse() free its allocated memory

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/torvalds/linux/commit/96c5c6e6a5b6db592acae039fed54b5c8844cd35

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2019-021c968423

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2019-34a75d7e61

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20191205-0001/

Source: UBUNTU
Type: Third Party Advisory
USN-4225-1

Source: UBUNTU
Type: Third Party Advisory
USN-4225-2

Source: UBUNTU
Type: Third Party Advisory
USN-4226-1

Vulnerable Configuration:Configuration 1:
  • cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version <= 5.3.11)
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/a:redhat:enterprise_linux:8::nfv:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/a:redhat:enterprise_linux:8::realtime:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201919072
    V
    CVE-2019-19072
    2023-06-22
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:685
    P
    Security update for bind (Important)
    2022-08-09
    oval:org.opensuse.security:def:665
    P
    Security update for samba (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:3453
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3567
    P
    libXtst6-1.2.2-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3448
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:1400
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important) (in QA)
    2022-06-27
    oval:org.opensuse.security:def:95078
    P
    reiserfs-kmp-default-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2960
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95083
    P
    kernel-azure-5.14.21-150400.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94590
    P
    kernel-64kb-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95197
    P
    kernel-default-extra-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95028
    P
    kernel-docs-5.14.21-150400.22.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:89
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1792
    P
    Security update for MozillaThunderbird (Important)
    2021-12-22
    oval:org.opensuse.security:def:49126
    P
    Security update for runc (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:66952
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:94182
    P
    (Important)
    2021-08-17
    oval:org.opensuse.security:def:2036
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63102
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2013
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100865
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100891
    P
    libXv-devel-1.0.11-1.23 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1018
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101277
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72738
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100895
    P
    libXxf86vm-devel-1.1.4-1.23 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63019
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101039
    P
    perl-Convert-ASN1-0.27-1.6.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71848
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1930
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100851
    P
    grub2-2.04-20.4 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62107
    P
    kernel-64kb-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:66860
    P
    Security update for ffmpeg (Important)
    2021-07-14
    oval:org.opensuse.security:def:94178
    P
    (Important)
    2021-07-14
    oval:org.opensuse.security:def:1465
    P
    Security update for postgresql13 (Moderate)
    2021-07-11
    oval:org.opensuse.security:def:69672
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:73643
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:66817
    P
    Security update for pam_radius (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:93741
    P
    (Important)
    2021-06-02
    oval:org.opensuse.security:def:70207
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:66759
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:70203
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:69777
    P
    Security update for subversion (Important)
    2021-02-10
    oval:org.opensuse.security:def:70308
    P
    Security update for python (Important)
    2021-02-09
    oval:org.opensuse.security:def:66851
    P
    Security update for go1.14 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:66725
    P
    Security update for libzypp, zypper (Moderate)
    2021-01-13
    oval:org.opensuse.security:def:70173
    P
    Security update for openssh (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:66421
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-11
    oval:org.opensuse.security:def:107705
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117220
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72678
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1999
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107517
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62959
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117075
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2534
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94326
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63114
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107557
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94138
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117115
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71515
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1870
    P
    kernel-docs-5.3.18-22.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100454
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61774
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2025
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107561
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63088
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117119
    P
    kernel-azure-5.3.18-16.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107120
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63623
    P
    kernel-default-extra-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116678
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49072
    P
    cpp7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73424
    P
    libgypsy-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49906
    P
    kernel-azure on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66329
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:49787
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73525
    P
    perl-Net-Libproxy on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50233
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73112
    P
    kernel-default on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72994
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:70068
    P
    libQt5OpenGLExtensions-devel-static on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49852
    P
    osc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73508
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73390
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49841
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70102
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50179
    P
    bogofilter-common on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73542
    P
    kernel-azure on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20204609
    P
    RHSA-2020:4609: kernel-rt security and bug fix update (Moderate)
    2020-11-04
    oval:com.redhat.rhsa:def:20204431
    P
    RHSA-2020:4431: kernel security, bug fix, and enhancement update (Moderate)
    2020-11-04
    oval:com.ubuntu.disco:def:2019190720000000
    V
    CVE-2019-19072 on Ubuntu 19.04 (disco) - medium.
    2019-11-18
    oval:com.ubuntu.bionic:def:2019190720000000
    V
    CVE-2019-19072 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-11-18
    oval:com.ubuntu.xenial:def:2019190720000000
    V
    CVE-2019-19072 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-11-18
    BACK
    canonical ubuntu linux 18.04
    canonical ubuntu linux 19.04
    canonical ubuntu linux 19.10
    fedoraproject fedora 30
    fedoraproject fedora 31
    linux linux kernel *
    redhat enterprise linux 8.0