Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libcacard | Libcacard_project | * | 2.5.3 (excluding) |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.9.0-10.el7 | * |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | qemu-kvm-rhev-10:2.9.0-10.el7 | * |
| Red Hat OpenStack Platform 10.0 (Newton) | RedHat | qemu-kvm-rhev-10:2.9.0-10.el7 | * |
| Red Hat OpenStack Platform 11.0 (Ocata) | RedHat | qemu-kvm-rhev-10:2.9.0-10.el7 | * |
| Red Hat OpenStack Platform 8.0 (Liberty) | RedHat | qemu-kvm-rhev-10:2.9.0-10.el7 | * |
| Red Hat OpenStack Platform 9.0 (Mitaka) | RedHat | qemu-kvm-rhev-10:2.9.0-10.el7 | * |
| Libcacard | Ubuntu | artful | * |
| Libcacard | Ubuntu | esm-infra/xenial | * |
| Libcacard | Ubuntu | upstream | * |
| Libcacard | Ubuntu | xenial | * |
| Libcacard | Ubuntu | yakkety | * |
| Libcacard | Ubuntu | zesty | * |