A memory leak in the cryptoreportstat() function in drivers/virt/vboxguest/vboxguestutils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copyformuser() failures, aka CID-e0b0cb938864.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19048.json"
[
{
"id": "CVE-2019-19048-194f311c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"251888028071254664368390594810663998980",
"171299447589504319952921104564848597711",
"128919409547117961403648579231265260065",
"189883247827109140699878165991638449196",
"123771784749525347373555357705805885295",
"149503746437094691156201536789924778678",
"118464741348516174421898124494461646143"
]
},
"signature_type": "Line",
"target": {
"file": "drivers/virt/vboxguest/vboxguest_utils.c"
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/e0b0cb9388642c104838fac100a4af32745621e2",
"deprecated": false
},
{
"id": "CVE-2019-19048-c9c0ac07",
"digest": {
"length": 608.0,
"function_hash": "123801147295231706399918601591238414667"
},
"signature_type": "Function",
"target": {
"file": "drivers/virt/vboxguest/vboxguest_utils.c",
"function": "hgcm_call_preprocess_linaddr"
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/e0b0cb9388642c104838fac100a4af32745621e2",
"deprecated": false
}
]