A memory leak in the bfadimgetstats() function in drivers/scsi/bfa/bfadattr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfaportget_stats() failures, aka CID-0e62395da2bd.
[
{
"id": "CVE-2019-19066-8116d627",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109210957428839699171763778773793832587",
"208699596530697932974510599209918787353",
"262558193400418876884440939335749067791",
"4368035887097760255379626330468517763",
"7946350080512775892571718888025792185"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/0e62395da2bd5166d7c9e14cbc7503b256a34cb0",
"signature_type": "Line",
"target": {
"file": "drivers/scsi/bfa/bfad_attr.c"
}
},
{
"id": "CVE-2019-19066-bbb01f52",
"signature_version": "v1",
"digest": {
"function_hash": "88074856535561178588270081904775275045",
"length": 1342.0
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/0e62395da2bd5166d7c9e14cbc7503b256a34cb0",
"signature_type": "Function",
"target": {
"file": "drivers/scsi/bfa/bfad_attr.c",
"function": "bfad_im_get_stats"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19066.json"