A memory leak in the sofsetgetlargectrldata() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sofgetctrlcopy_params() failures, aka CID-45c1380358b1.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18811.json"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"152981478712669551806896510150614400149",
"298032684525279642771470640267076223337",
"164708425382779643950103415437346668942",
"102894814267180558311056886863031106244",
"206816665977361374390959206709759038592"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2019-18811-178ca3cd",
"source": "https://github.com/torvalds/linux/commit/45c1380358b12bf2d1db20a5874e9544f56b34ab",
"target": {
"file": "sound/soc/sof/ipc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1164.0,
"function_hash": "132568483307396979849899859045455457252"
},
"signature_type": "Function",
"id": "CVE-2019-18811-b1762955",
"source": "https://github.com/torvalds/linux/commit/45c1380358b12bf2d1db20a5874e9544f56b34ab",
"target": {
"function": "sof_set_get_large_ctrl_data",
"file": "sound/soc/sof/ipc.c"
}
}
]