7.8

CVE-2019-16995

Exploit

In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.17 < 3.18.137
LinuxLinux Kernel Version >= 4.4 < 4.4.177
LinuxLinux Kernel Version >= 4.9 < 4.9.164
LinuxLinux Kernel Version >= 4.14 < 4.14.107
LinuxLinux Kernel Version >= 4.19 < 4.19.30
LinuxLinux Kernel Version >= 4.20 < 4.20.17
LinuxLinux Kernel Version >= 5.0 < 5.0.3
LinuxLinux Kernel Version5.1 Updaterc1
OpensuseLeap Version15.0
OpensuseLeap Version15.1
NetappAff A700s Firmware Version-
   NetappAff A700s Version-
NetappH300s Firmware Version-
   NetappH300s Version-
NetappH500s Firmware Version-
   NetappH500s Version-
NetappH700s Firmware Version-
   NetappH700s Version-
NetappH300e Firmware Version-
   NetappH300e Version-
NetappH500e Firmware Version-
   NetappH500e Version-
NetappH700e Firmware Version-
   NetappH700e Version-
NetappH410s Firmware Version-
   NetappH410s Version-
NetappH410c Firmware Version-
   NetappH410c Version-
NetappH610s Firmware Version-
   NetappH610s Version-
NetappService Processor Version-
NetappSolidfire Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2% 0.82
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.