A memory leak in the cryptoreportstat() function in crypto/cryptouserstat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering cryptoreportstat_alg() failures, aka CID-c03b04dcdba1.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19050.json"
[
{
"id": "CVE-2019-19050-571a75eb",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"172691057137977566628016591001604315723",
"104231520949033327869045788447989232036",
"280136109743154519411802112923050193380",
"4810305325259325721337508899659012635",
"58849939127738932200321272600655345012"
]
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/c03b04dcdba1da39903e23cc4d072abf8f68f2dd",
"target": {
"file": "crypto/crypto_user_stat.c"
},
"deprecated": false
},
{
"id": "CVE-2019-19050-d28090cd",
"signature_type": "Function",
"digest": {
"function_hash": "125760437613930756285443968798150978998",
"length": 725.0
},
"signature_version": "v1",
"source": "https://github.com/torvalds/linux/commit/c03b04dcdba1da39903e23cc4d072abf8f68f2dd",
"target": {
"function": "crypto_reportstat",
"file": "crypto/crypto_user_stat.c"
},
"deprecated": false
}
]