CVE-2019-19070

A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
linuxlinux_kernel
4.17 ≤
𝑥
< 5.4.7
linuxlinux_kernel
5.5:rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bullseye
unimportant
bullseye (security)
unimportant
bookworm
unimportant
bookworm (security)
unimportant
trixie
unimportant
sid
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
linux-aws
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
linux-aws-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-aws-hwe
eoan
dne
disco
dne
bionic
dne
xenial
not-affected
trusty
dne
linux-azure
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored
linux-azure-5.3
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-azure-edge
eoan
dne
disco
dne
bionic
ignored
xenial
ignored
trusty
dne
linux-gcp
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
linux-gcp-5.3
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-gcp-edge
eoan
dne
disco
dne
bionic
ignored
xenial
dne
trusty
dne
linux-gke-4.15
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-gke-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-gke-5.3
eoan
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-hwe
eoan
dne
disco
dne
bionic
not-affected
xenial
not-affected
trusty
dne
linux-hwe-edge
eoan
dne
disco
dne
bionic
not-affected
xenial
ignored
trusty
dne
linux-kvm
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
linux-lts-trusty
eoan
dne
disco
dne
bionic
dne
xenial
dne
trusty
dne
linux-lts-xenial
eoan
dne
disco
dne
bionic
dne
xenial
dne
trusty
ignored
linux-oem
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
ignored
trusty
dne
linux-oem-5.4
eoan
dne
bionic
dne
xenial
dne
trusty
dne
linux-oem-osp1
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
dne
trusty
dne
linux-oracle
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
linux-oracle-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-raspi2
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
linux-raspi2-5.3
eoan
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-snapdragon
eoan
dne
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne