---
id: CVE-2019-19066
title: >-
  A memory leak in the bfad_im_get_stats() function in
  drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows
  attackers to cause a denial of service (memory consumption) by triggering
  bfa_port_get_stats() failures, aka CID-…
summary: >-
  A memory leak in the bfad_im_get_stats() function in
  drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows
  attackers to cause a denial of service (memory consumption) by triggering
  bfa_port_get_stats() failures, aka CID-…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-401
vendor: linux
product: linux_kernel
affected:
  - linux_kernel <= 5.3.11
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - ubuntu_linux = 19.10
  - debian_linux = 8.0
  - fedora = 30
  - fedora = 31
  - leap = 15.1
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
published: '2019-11-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:17.927'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-19066'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html'
    label: cve@mitre.org
  - url: >-
      https://github.com/torvalds/linux/commit/0e62395da2bd5166d7c9e14cbc7503b256a34cb0
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3PSDE6PTOTVBK2YTKB2TFQP2SUBVSNF/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PY7LJMSPAGRIKABJPDKQDTXYW3L5RX2T/
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20191205-0001/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4286-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4286-2/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4300-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4301-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4302-1/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/torvalds/linux/commit/0e62395da2bd5166d7c9e14cbc7503b256a34cb0
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3PSDE6PTOTVBK2YTKB2TFQP2SUBVSNF/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PY7LJMSPAGRIKABJPDKQDTXYW3L5RX2T/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20191205-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4286-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4286-2/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4300-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4301-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4302-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00452
epssPercentile: 0.37269
ingestedAt: '2026-10-08T22:11:53.705Z'
---

## Overview

A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.

## Affected

- `linux_kernel <= 5.3.11`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 19.10`
- `debian_linux = 8.0`
- `fedora = 30`
- `fedora = 31`
- `leap = 15.1`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
