Bugzilla – Bug 1159374
VUL-0: CVE-2019-18811: kernel-source: memory leak in sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c
Last modified: 2024-06-25 14:12:15 UTC
CVE-2019-18811 A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures. Reference: https://github.com/torvalds/linux/commit/45c1380358b12bf2d1db20a5874e9544f56b34ab References: https://bugzilla.redhat.com/show_bug.cgi?id=1777455 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18811 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-18811.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18811 https://github.com/torvalds/linux/commit/45c1380358b12bf2d1db20a5874e9544f56b34ab https://security.netapp.com/advisory/ntap-20191205-0001/
All codestreams are not affected. SLE15-SP2 is already in a fixed version and contains the fix.