7.8

CVE-2019-16995

Exploit
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.17 < 3.18.137
Linux ≫ Linux Kernel Version >= 4.4 < 4.4.177
Linux ≫ Linux Kernel Version >= 4.9 < 4.9.164
Linux ≫ Linux Kernel Version >= 4.14 < 4.14.107
Linux ≫ Linux Kernel Version >= 4.19 < 4.19.30
Linux ≫ Linux Kernel Version >= 4.20 < 4.20.17
Linux ≫ Linux Kernel Version >= 5.0 < 5.0.3
Linux ≫ Linux Kernel Version 5.1 Update rc1
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Netapp ≫ Aff A700s Firmware Version -
   Netapp ≫ Aff A700s Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Service Processor Version -
Netapp ≫ Solidfire Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.53% 0.877
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20191031-0005/
Third Party Advisory
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.3
Vendor Advisory
Exploit
Release Notes
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6caabe7f197d3466d238f70915d65301f1716626
Patch
Vendor Advisory
https://github.com/torvalds/linux/commit/6caabe7f197d3466d238f70915d65301f1716626
Patch
Third Party Advisory