Bugzilla – Bug 1156278
VUL-1: CVE-2019-18813: kernel-source: memory leak in dwc3_pci_probe() from drivers/usb/dwc3/dwc3-pci.c
Last modified: 2024-06-25 14:04:30 UTC
CVE-2019-18813 A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18813 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18813 https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9bbfceea12a8f145097a27d7c7267af25893c060
The Fixes tag suggests the bug is since 4.19 kernel, so only SLE15-SP2 and TW are affected.
... and SLE15-SP2 already has the fix. I'll update the patch reference.
The fix reference and patch merged to SLE15-SP2 and stable branches. Reassigned back to security team.
done