CVE-2019-19067: Canonical Ubuntu Linux

Medium severity, CVSS 4.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.04 only; version 19.10 only
  • Linux Linux Kernel: before 5.3.8 (fixed in 5.3.8)
  • Opensuse Leap: version 15.1 only

Published 2019-11-18. Last modified 2026-06-17.