Bugzilla – Bug 1157336
VUL-1: CVE-2019-19050: kernel-source: memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c
Last modified: 2024-06-25 14:07:40 UTC
CVE-2019-19050 A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-19050 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-19050.html https://github.com/torvalds/linux/commit/c03b04dcdba1da39903e23cc4d072abf8f68f2dd http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19050
pretty similar to bsc#1157333 only seems relevant for SLE15-SP2
Will backport once when the fix gets merged to Linus tree. This one is indeed only in SLE15-SP2 and later.
Backported to SLE15-SP2 branch. Reassigned back to security team.
closing