A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot
2019-11-18T06:15:11.640
2025-03-07T14:37:52.380
Analyzed
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 4.4.200 | Yes |
Operating System | linux | linux_kernel | < 4.9.200 | Yes |
Operating System | linux | linux_kernel | < 4.14.153 | Yes |
Operating System | linux | linux_kernel | < 4.19.83 | Yes |
Operating System | linux | linux_kernel | < 5.3.10 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |