A memory leak in the ccprunsha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.
[
{
"id": "CVE-2019-18808-1fdf5890",
"signature_version": "v1",
"digest": {
"function_hash": "260837460471490098833873997995077216059",
"length": 6469.0
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/128c66429247add5128c03dc1e144ca56f05a4e2",
"signature_type": "Function",
"target": {
"file": "drivers/crypto/ccp/ccp-ops.c",
"function": "ccp_run_sha_cmd"
}
},
{
"id": "CVE-2019-18808-5a0b91ca",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"254874690942283278958720239003035550319",
"112489412379212029628658987455508431152",
"288507025947740280330572848968720621868",
"308201895836943838344400073954246249830",
"210138289811109314451985436886772388552",
"55707371958197591229665743033628446113"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/128c66429247add5128c03dc1e144ca56f05a4e2",
"signature_type": "Line",
"target": {
"file": "drivers/crypto/ccp/ccp-ops.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18808.json"