Memory leak in Linux kernel - CVE-2019-16994
Published: May 30, 2024
Vulnerability identifier: #VU90044
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-16994
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak within the sit_init_net() function in net/ipv6/sit.c. A local user can perform denial of service attack.
Affected software
Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Workstation
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux Workstation
kernel (Red Hat package)
kernel-rt (Red Hat package)
How to mitigate CVE-2019-16994
Install updates from vendor's website.
kernel (Red Hat package) - update to 3.10.0-1160.el7
kernel-rt (Red Hat package) - update to 3.10.0-1160.rt56.1131.el7
kernel-rt (Red Hat package) - update to 3.10.0-1160.rt56.1131.el7
External References
- https://github.com/torvalds/linux/commit/07f12b26e21ab359261bf75cfcb424fdc7daeb6d
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=07f12b26e21ab359261bf75cfcb424fdc7daeb6d
- https://security.netapp.com/advisory/ntap-20191031-0005/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html