PT-2020-10766 · Linux+4 · Iproute2+4

Published

2019-05-15

·

Updated

2021-10-18

·

CVE-2019-20795

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iproute2 versions prior to 5.1.0
Description The issue is related to a use-after-free in the get netnsid from name function in ip/ipnetns.c. This may have limited security relevance, particularly in certain configurations where setuid is used, although other factors such as C library configuration may affect exploitability.
Recommendations For versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of setuid configurations to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1829
CVE-2019-20795
SUSE-SU-2021:3452-1
SUSE-SU-2021_3452-1
USN-4357-1

Affected Products

Alt Linux
Astra Linux
Suse
Ubuntu
Iproute2