Resource exhaustion in Linux kernel - CVE-2019-15118
Published: October 23, 2019
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of recursion within the check_input_term() function in sound/usb/mixer.c. A local user can run a specially crafted application to trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Slackware Linux
linux-4.4.199/kernel-generic
linux-4.4.199/kernel-huge
linux-4.4.199/kernel-modules
linux-4.4.199/kernel-headers
How to mitigate CVE-2019-15118
linux-4.4.199/kernel-generic - update to 4.4.199
linux-4.4.199/kernel-huge - update to 4.4.199
linux-4.4.199/kernel-modules - update to 4.4.199
linux-4.4.199/kernel-headers - update to 4.4.199_smp