Vulnerability Description
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.17, < 3.18.137 |
| Opensuse | Leap | 15.0 |
| Netapp | Aff A700S Firmware | - |
| Netapp | Aff A700S | - |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H300E Firmware | - |
| Netapp | H300E | - |
| Netapp | H500E Firmware | - |
| Netapp | H500E | - |
| Netapp | H700E Firmware | - |
| Netapp | H700E | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
| Netapp | H410C Firmware | - |
| Netapp | H410C | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.htmlMailing ListThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.3ExploitRelease NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6caabPatchVendor Advisory
- https://github.com/torvalds/linux/commit/6caabe7f197d3466d238f70915d65301f171662PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.htmlMailing ListThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.3ExploitRelease NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6caabPatchVendor Advisory
- https://github.com/torvalds/linux/commit/6caabe7f197d3466d238f70915d65301f171662PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/Third Party Advisory
FAQ
What is CVE-2019-16995?
CVE-2019-16995 is a vulnerability with a CVSS score of 7.5 (HIGH). In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
How severe is CVE-2019-16995?
CVE-2019-16995 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16995?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Opensuse Leap, Netapp Aff A700S Firmware, Netapp Aff A700S, Netapp H300S Firmware.