CVE-2019-19049: Linux Kernel

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot

Affected products

  • Linux Linux Kernel: from 3.17, before 4.4.200 (fixed in 4.4.200); from 4.5, before 4.9.200 (fixed in 4.9.200); from 4.10, before 4.14.153 (fixed in 4.14.153); from 4.15, before 4.19.83 (fixed in 4.19.83); from 4.20, before 5.3.10 (fixed in 5.3.10)
  • Opensuse Leap: version 15.1 only

Published 2019-11-18. Last modified 2026-06-17.