CVE-2019-16994: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.

Affected products

  • Linux Linux Kernel: before 5.0 (fixed in 5.0)
  • Opensuse Leap: version 15.1 only
  • Red Hat Enterprise Linux: version 7.0 only

Published 2019-09-30. Last modified 2026-06-17.