PT-2019-4140 · Linux+4 · Linux Kernel+4

Published

2019-03-01

·

Updated

2025-12-26

·

CVE-2019-15666

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0.19
Description The issue is related to an out-of-bounds array access in the xfrm policy unlink component of the Linux kernel, which can cause a denial of service. This is due to the verify newpolicy info function in net/xfrm/xfrm user.c mishandling directory validation. There have been reports of real-world incidents where this issue was exploited, resulting in the compromise of several large computational clusters in supercomputer centers in the UK, Germany, Switzerland, and Spain. The attackers exploited the vulnerability to gain root access and install malware for hidden cryptocurrency mining. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For Linux kernel versions prior to 5.0.19, update to version 5.0.19 or later to resolve the issue. As a temporary workaround, consider restricting access to the xfrm policy unlink component until a patch is available. Avoid using the verify newpolicy info function in the affected net/xfrm/xfrm user.c file until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1893
ALT-PU-2019-1896
ALT-PU-2019-1925
ALT-PU-2019-2077
ALT-PU-2020-1198
ALT-PU-2020-1501
ALT-PU-2020-2410
ALT-PU-2020-2433
ALT-PU-2021-1870
BDU:2019-04720
CESA-2019_3309
CESA-2019_3517
CVE-2019-15666
DLA-1919-1
DLA-1919-2
OPENSUSE-SU-2019:2173-1
OPENSUSE-SU-2019:2181-1
OPENSUSE-SU-2019_2173-1
OPENSUSE-SU-2019_2181-1
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:1493
SUSE-SU-2019:2412-1
SUSE-SU-2019:2414-1
SUSE-SU-2019:2424-1
SUSE-SU-2019:2648-1
SUSE-SU-2019:2651-1
SUSE-SU-2019:2658-1
SUSE-SU-2019:2738-1
SUSE-SU-2019:2756-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2984-1
SUSE-SU-2020:1656-1
SUSE-SU-2020:1671-1
SUSE-SU-2020:1758-1
SUSE-SU-2020:1767-1
SUSE-SU-2020:1784-1
SUSE-SU-2020_1656-1
SUSE-SU-2020_1671-1
SUSE-SU-2020_1767-1
SUSE-SU-2020_1784-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse