Memory leak in Linux kernel - CVE-2019-15807

 

Memory leak in Linux kernel - CVE-2019-15807

Published: August 29, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30802
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15807
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service. A remote attacker can perform a denial of service attack.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Workstation
kernel (Red Hat package)
kernel-rt (Red Hat package)
RSA Authentication Manager

How to mitigate CVE-2019-15807

Update to version 5.1.13.

Linux kernel - update to 5.1.13
kernel (Red Hat package) - update to 3.10.0-1160.el7
kernel-rt (Red Hat package) - update to 3.10.0-1160.rt56.1131.el7
RSA Authentication Manager - update to 8.4 Patch 9

External References

Related Security Bulletins