PT-2019-4975 · Linux+3 · Linux Kernel+3

Published

2016-03-17

·

Updated

2021-07-21

·

CVE-2019-11815

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.0.8
Description The issue is caused by a race condition in the rds tcp kill sock function, leading to a use-after-free error related to net namespace cleanup. This can potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is associated with the Reliable Datagram Socket (RDS) TCP socket implementation in the Linux kernel.
Recommendations For Linux kernel versions prior to 5.0.8, update to version 5.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable rds tcp kill sock function until a patch is available.

Exploit

Fix

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1262
ALT-PU-2017-1299
ALT-PU-2018-1557
ALT-PU-2019-1139
ALT-PU-2019-1363
ALT-PU-2019-1665
ALT-PU-2019-1666
ALT-PU-2019-1710
BDU:2020-01595
CVE-2019-11815
DLA-1824-1
DSA-4465-1
OPENSUSE-SU-2019:1404-1
OPENSUSE-SU-2019:1479-1
OPENSUSE-SU-2019_1404-1
OPENSUSE-SU-2019_1407-1
OPENSUSE-SU-2019_1479-1
SUSE-SU-2019:1527-1
SUSE-SU-2019:1529-1
SUSE-SU-2019:1530-1
SUSE-SU-2019:1532-1
SUSE-SU-2019:1534-1
SUSE-SU-2019:1535-1
SUSE-SU-2019:1536-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:2430-1
USN-4005-1
USN-4008-1
USN-4008-3
USN-4068-1
USN-4068-2
USN-4118-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu