Vulnerability Description
A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.7, < 4.9.163 |
| Canonical | Ubuntu Linux | 14.04 |
| Opensuse | Leap | 15.0 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00052.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107120Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlMailing ListThird Party Advisory
- https://support.f5.com/csp/article/K56480726Third Party Advisory
- https://usn.ubuntu.com/3930-1/Third Party Advisory
- https://usn.ubuntu.com/3930-2/Third Party Advisory
- https://usn.ubuntu.com/3931-1/Third Party Advisory
- https://usn.ubuntu.com/3931-2/Third Party Advisory
- https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1935698.html
- https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1935705.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00052.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107120Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2019/05/msg00002.htmlMailing ListThird Party Advisory
- https://support.f5.com/csp/article/K56480726Third Party Advisory
- https://usn.ubuntu.com/3930-1/Third Party Advisory
FAQ
What is CVE-2019-8980?
CVE-2019-8980 is a vulnerability with a CVSS score of 7.5 (HIGH). A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
How severe is CVE-2019-8980?
CVE-2019-8980 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8980?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Opensuse Leap, Debian Debian Linux.