PT-2019-3348 · Linux+4 · Linux Kernel+4

Published

2019-09-05

·

Updated

2026-03-14

·

CVE-2019-16089

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.2.14
Description The issue is related to the nbd genl status function in the Linux kernel, specifically in the drivers/block/nbd.c file. It does not check the return value of nla nest start noflag, which can lead to pointer dereference errors. An attacker could potentially exploit this issue to cause a denial of service using a specially crafted application.
Recommendations For Linux kernel versions prior to 5.2.14, update to version 5.2.14 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2673
ALT-PU-2019-2745
ALT-PU-2019-2746
ALT-PU-2019-2768
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-03478
CVE-2019-16089
ECHO-F07B-34E3-47BE
OESA-2021-1086
OESA-2021-1087
USN-4414-1
USN-4425-1
USN-4439-1
USN-4440-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Ubuntu